CVE · Medium

CVE-2023-6257 — Inline Related Posts [intelly-related-posts] < 3.6.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6257 Inline Related Posts [intelly-related-posts] < 3.6.0 Missing Authorization Medium 4.3 < 3.6.0 3.6.0 2024-03-21

CVE-2023-6257

The Inline Related Posts plugin before version 3.6.0 contains a sensitive information exposure flaw in the irp_get_list_posts() function that allows authenticated users with subscriber privileges or higher to access the content of password-protected posts. Any logged-in user at the subscriber level and above can exploit this vulnerability to retrieve restricted post content that should only be viewable by those with the proper password.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.