Authenticated Attackers Can Expose Sensitive Post Metadata
CVE-2023-7049
4.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 16 August 2024
What is CVE-2023-7049?
The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2 via the the 'cm_fieldshow' shortcode due to missing validation on the 'job_id' user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to expose potentially sensitive post metadata.
Affected Version(s)
Custom Field For WP Job Manager * <= 1.2