CVE-2023-5692

WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to expose the slug of a custom post whose 'publicly_queryable' post status has been set to 'false'.
Configurations

No configuration.

History

No history.

Information

Published : 2024-04-05 13:15

Updated : 2026-06-17 06:49


NVD link : CVE-2023-5692

Mitre link : CVE-2023-5692

CVE.ORG link : CVE-2023-5692


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor