VYPR
Unrated severityNVD Advisory· Published Oct 16, 2023· Updated Apr 23, 2025

WordPress < 6.3.2 - Unauthenticated Post Author Email Disclosure

CVE-2023-5561

Description

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.