The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2022.0222 due to missing validation on the user controlled 'guid' key. This makes it possible for unauthenticated attackers to view draft posts that may contain sensitive information.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Mar 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Feedwordpress Project
Feedwordpress Project feedwordpress |
|
Weaknesses | CWE-639 | |
CPEs | cpe:2.3:a:feedwordpress_project:feedwordpress:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Feedwordpress Project
Feedwordpress Project feedwordpress |

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-28T16:13:15.063Z
Reserved: 2024-01-23T20:52:44.850Z
Link: CVE-2024-0839

Updated: 2024-08-01T18:18:18.715Z

Status : Analyzed
Published: 2024-03-13T16:15:14.537
Modified: 2025-03-11T13:25:38.507
Link: CVE-2024-0839

No data.