CVE Database
/

CVE-2023-0749

Back to search

CVE-2023-0749

Published: Mar 13, 2023

Modified: Feb 27, 2025

PUBLISHED

Description

The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones.

VendorProductVersions

Unknown

Ocean Extra

affected
0 - < 2.1.3

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now