CVE · Medium

CVE-2023-26533 — Zippy [zippy] < 1.6.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-26533 Zippy [zippy] < 1.6.2 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.5 < 1.6.2 1.6.2 2023-03-30

CVE-2023-26533

The Zippy plugin for WordPress through version 1.6.1 contains a sensitive information disclosure flaw in the adminInit function that permits authenticated users with post editing permissions, including contributors, to export data containing sensitive details like usernames and password hashes. This vulnerability was patched in version 1.6.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.