HomeDefault status
unaffected
Any version before 3.11.3
affected
Description
The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied query parameter, allowing unauthenticated attackers to retrieve the titles and content of private, draft, and other non-public posts.
Problem types
Product status
Any version before 3.11.3
Credits
Ahmed Hashim Ismael
WPScan
References
wpscan.com/...rability/b55ebf9e-a05d-4ae4-b653-da7db63e76d2/