CVE · Medium

CVE-2023-0749 — Ocean Extra [ocean-extra] < 2.1.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-0749 Ocean Extra [ocean-extra] < 2.1.3 Authorization Bypass Through User-Controlled Key Medium 6.5 < 2.1.3 2.1.3 2023-02-14

CVE-2023-0749

The Ocean Extra plugin for WordPress through version 2.1.2 contains a flaw in the oceanwp_library shortcode that fails to check whether a post has been published before displaying its content. Attackers with subscriber-level access or higher can exploit this vulnerability to view private or draft posts that should not be accessible to them. The issue allows unauthorized disclosure of sensitive post content that was intended to be restricted. This vulnerability was patched in version 2.1.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.