Front End PM < 11.4.3 - Sensitive Data Exposure via Directory Listing
CVE-2023-4930

6.5MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
6 November 2023

Summary

The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.

Affected Version(s)

Front End PM 0 < 11.4.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
WPScan
.