CVE-2023-1623
The Custom Post Type UI plugin for WordPress through version 1.13.4 contains a cross-site request forgery vulnerability in the cptui_render_debuginfo_section function due to inadequate nonce validation. An unauthenticated attacker could exploit this by crafting a malicious request that, if clicked by an administrator, would leak sensitive debug information including installed plugins and themes along with version details for PHP, MySQL, and the web server. The vulnerability was patched in version 1.13.5.
Based on public CVE data (MITRE/NVD).