Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Apusthemes Subscribe
Filtered by product Wp Private Messaging
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-0453 1 Apusthemes 1 Wp Private Messaging 2023-03-02 N/A 4.3 MEDIUM
The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID.