CVE · Medium

CVE-2023-1623 — Custom Post Type UI [custom-post-type-ui] < 1.13.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-1623 Custom Post Type UI [custom-post-type-ui] < 1.13.5 Cross-Site Request Forgery (CSRF) Medium 6.5 < 1.13.5 1.13.5 2023-03-28

CVE-2023-1623

The Custom Post Type UI plugin for WordPress through version 1.13.4 contains a cross-site request forgery vulnerability in the cptui_render_debuginfo_section function due to inadequate nonce validation. An unauthenticated attacker could exploit this by crafting a malicious request that, if clicked by an administrator, would leak sensitive debug information including installed plugins and themes along with version details for PHP, MySQL, and the web server. The vulnerability was patched in version 1.13.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.