Medium severity6.5NVD Advisory· Published Apr 9, 2024· Updated Apr 8, 2026
CVE-2023-6695
CVE-2023-6695
Description
The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the 'wpbb' shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including arbitrary user_meta values.
Affected products
2cpe:2.3:a:fastlinemedia:beaver_themer:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fastlinemedia:beaver_themer:*:*:*:*:*:*:*:*range: <1.4.9.1
- (no CPE)range: <=1.4.9
Patches
Vulnerability mechanics
References
2- www.wordfence.com/threat-intel/vulnerabilities/id/4165cff7-457d-4790-8678-84c4365a191anvdThird Party Advisory
- www.wpbeaverbuilder.com/change-logs/nvdProduct
News mentions
0No linked articles in our index yet.