WordPress Plugin Vulnerabilities
Simple Author Box < 2.52 - Contributor+ Arbitrary User Information Disclosure via IDOR
Description
The plugin does not verify a user ID before outputting information about that user, leading to arbitrary user information disclosure to users with a role as low as Contributor.
Proof of Concept
Affects Plugins
References
Classification
Type
IDOR
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Dmitriy
Submitter
Dmitriy
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2023-07-24 (about 2 years ago)
Added
2023-07-24 (about 2 years ago)
Last Updated
2023-08-22 (about 2 years ago)