{ "id": "CVE-2023-4036", "sourceIdentifier": "contact@wpscan.com", "published": "2023-08-30T15:15:09.813", "lastModified": "2023-08-31T10:02:10.690", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public, allowing any authenticated users, such as subscriber, to retrieve arbitrary post title and their content such as draft, private and password protected ones" } ], "metrics": {}, "weaknesses": [ { "source": "contact@wpscan.com", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-639" } ] } ], "references": [ { "url": "https://wpscan.com/vulnerability/de3e1718-c358-4510-b142-32896ffeb03f", "source": "contact@wpscan.com" } ] }