CVE-2023-5561

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/10/2023
Last modified:
23/04/2025

Description

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 4.7 (including) 4.7.27 (excluding)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 4.8 (including) 4.8.23 (excluding)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 4.9 (including) 4.9.24 (excluding)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 5.0 (including) 5.0.20 (excluding)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 5.1 (including) 5.1.17 (excluding)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 5.2 (including) 5.2.19 (excluding)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 5.3 (including) 5.3.16 (excluding)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 5.4 (including) 5.4.14 (excluding)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 5.5 (including) 5.5.13 (excluding)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 5.6 (including) 5.6.12 (excluding)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 5.7 (including) 5.7.10 (excluding)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 5.8 (including) 5.8.8 (excluding)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 5.9 (including) 5.9.8 (excluding)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 6.0 (including) 6.0.6 (excluding)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* 6.1 (including) 6.1.4 (excluding)