{"id":"CVE-2023-39999","summary":"WordPress \u003c 6.3.2 is vulnerable to Broken Access Control","details":"Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38.","aliases":["BIT-wordpress-2023-39999","BIT-wordpress-multisite-2023-39999"],"modified":"2026-07-11T03:54:54.874711019Z","published":"2023-10-13T11:31:16.977Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/39xxx/CVE-2023-39999.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"6.3"},{"last_affected":"6.3.1"},{"introduced":"6.2"},{"last_affected":"6.2.2"},{"introduced":"6.1"},{"last_affected":"6.13"},{"introduced":"6.0"},{"last_affected":"6.0.5"},{"introduced":"5.9"},{"last_affected":"5.9.7"},{"introduced":"5.8"},{"last_affected":"5.8.7"},{"introduced":"5.7"},{"last_affected":"5.7.9"},{"introduced":"5.6"},{"last_affected":"5.6.11"},{"introduced":"5.5"},{"last_affected":"5.5.12"},{"introduced":"5.4"},{"last_affected":"5.4.13"},{"introduced":"5.3"},{"last_affected":"5.3.15"},{"introduced":"5.2"},{"last_affected":"5.2.18"},{"introduced":"5.1"},{"last_affected":"5.1.16"},{"introduced":"5.0"},{"last_affected":"5.0.19"},{"introduced":"4.9"},{"last_affected":"4.9.23"},{"introduced":"4.8"},{"last_affected":"4.8.22"},{"introduced":"4.7"},{"last_affected":"4.7.26"},{"introduced":"4.6"},{"last_affected":"4.6.26"},{"introduced":"4.5"},{"last_affected":"4.5.29"},{"introduced":"4.4"},{"last_affected":"4.4.30"},{"introduced":"4.3"},{"last_affected":"4.3.31"},{"introduced":"4.2"},{"last_affected":"4.2.35"},{"introduced":"4.1"},{"last_affected":"4.1.38"}]},{"extracted_events":[{"introduced":"6.3"},{"fixed":"6.3.1"},{"introduced":"6.2"},{"fixed":"6.2.2"},{"introduced":"6.1"},{"fixed":"6.13"},{"introduced":"6.0"},{"fixed":"6.0.5"},{"introduced":"5.9"},{"fixed":"5.9.7"},{"introduced":"5.8"},{"fixed":"5.8.7"},{"introduced":"5.7"},{"fixed":"5.7.9"},{"introduced":"5.6"},{"fixed":"5.6.11"},{"introduced":"5.5"},{"fixed":"5.5.12"},{"introduced":"5.4"},{"fixed":"5.4.13"},{"introduced":"5.3"},{"fixed":"5.3.15"},{"introduced":"5.2"},{"fixed":"5.2.18"},{"introduced":"5.1"},{"fixed":"5.1.16"},{"introduced":"5.0"},{"fixed":"5.0.19"},{"introduced":"4.9"},{"fixed":"4.9.23"},{"introduced":"4.8"},{"fixed":"4.8.22"},{"introduced":"4.7"},{"fixed":"4.7.26"},{"introduced":"4.6"},{"fixed":"4.6.26"},{"introduced":"4.5"},{"fixed":"4.5.29"},{"introduced":"4.4"},{"fixed":"4.4.30"},{"introduced":"4.3"},{"fixed":"4.3.31"},{"introduced":"4.2"},{"fixed":"4.2.35"},{"introduced":"4.1"},{"fixed":"4.1.38"}],"source":"DESCRIPTION"}],"cna_assigner":"Patchstack","cwe_ids":["CWE-200"]},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/11/msg00014.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2EVFT4DPZRFTXJPEPADM22BZVIUD2P66/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCCVDPKOK57WCTH2QJ5DJM3B53RJNZKA/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WQBL4ZQCBFNQ76XHM5257CIBFQRGT5QY/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/39xxx/CVE-2023-39999.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-39999"},{"type":"ADVISORY","url":"https://patchstack.com/articles/wordpress-core-6-3-2-security-update-technical-advisory?_s_id=cve"},{"type":"ADVISORY","url":"https://patchstack.com/database/vulnerability/wordpress/wordpress-wordpress-core-core-6-3-2-contributor-comment-read-on-private-and-password-protected-post-vulnerability?_s_id=cve"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wordpress/wordpress","events":[{"introduced":"e5e791f331d371ad6262c1893d84f5f2b6c26464"},{"introduced":"87bf150016e042bc3e21f2f1cb9de44042b8cdb1"},{"introduced":"b57f3aa5f00a127f209eff74b78787dd3fd5ed4d"},{"introduced":"f6a29831c76d2dbe82e9ae673539f910654c58a4"},{"introduced":"e3aafee3f2bc07e09bf79389f20ea3db731466c3"},{"introduced":"fe47e6139dbfc0f0c9ce0d79da77926b5fceaa77"},{"introduced":"14247ee4302378d292863865c643abe99bbfe3c7"},{"introduced":"06fa4161aa74619239cf27017d124081c825684a"},{"introduced":"29ffbff370968ae48a1b7a34e35c8b8e75cf0f91"},{"introduced":"491c67be12ca8a9fe37ae38307ba7e298c976ec3"},{"introduced":"c33464a4554cff8a082bc353d9226d8104b80d2b"},{"introduced":"6fe64752be3260f2a47f38e68c2cb77400e5a0c9"},{"introduced":"50dc0ca5bb332c895f0f39fe4e6ee1e4a43e06dc"},{"introduced":"9ff4499281663b0c772787fd4a60538288f842e9"},{"introduced":"537fd931bc02e6e934a2d774422b897871aa87ad"},{"introduced":"965fcddcf68cf4fd122ae24b992e242dfea1d773"},{"introduced":"058f9903676a7efaee534a682df0a2a8b87574d8"},{"introduced":"50caeb6e61ad0c49d2c7e1d6d5115047a011f590"},{"introduced":"73157386d069425c5e6ea7c4fc0122e8a9b58a7b"},{"introduced":"cc101b64012b16d087780657a2b828ccd7794a63"},{"introduced":"6c5d5b5dcb9712bfc400b09cb6627e42898527af"},{"introduced":"17e2eff4aa3beb2802cbec12b6f08e2fbf69893d"},{"introduced":"ac3899153a790a6f060dc816ff94812e0fd99875"},{"fixed":"ffb401296259cc20eed753bf0f934221df45e32e"}],"database_specific":{"cpe":"cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.1"},{"last_affected":"4.1.38"},{"introduced":"4.2"},{"last_affected":"4.2.35"},{"introduced":"4.3"},{"last_affected":"4.3.31"},{"introduced":"4.4"},{"last_affected":"4.4.30"},{"introduced":"4.5"},{"last_affected":"4.5.29"},{"introduced":"4.6"},{"last_affected":"4.6.26"},{"introduced":"4.7"},{"last_affected":"4.7.26"},{"introduced":"4.8"},{"last_affected":"4.8.22"},{"introduced":"4.9"},{"last_affected":"4.9.23"},{"introduced":"5.0"},{"last_affected":"5.0.19"},{"introduced":"5.1"},{"last_affected":"5.1.16"},{"introduced":"5.2"},{"last_affected":"5.2.18"},{"introduced":"5.3"},{"last_affected":"5.3.15"},{"introduced":"5.4"},{"last_affected":"5.4.13"},{"introduced":"5.5"},{"last_affected":"5.5.12"},{"introduced":"5.6"},{"last_affected":"5.6.11"},{"introduced":"5.7"},{"last_affected":"5.7.9"},{"introduced":"5.8"},{"last_affected":"5.8.7"},{"introduced":"5.9"},{"last_affected":"5.9.7"},{"introduced":"6.0"},{"last_affected":"6.0.5"},{"introduced":"6.1"},{"last_affected":"6.1.3"},{"introduced":"6.2"},{"last_affected":"6.2.2"},{"introduced":"6.3"},{"fixed":"6.3.2"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-39999.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/wordpress/wordpress-develop","events":[{"introduced":"470529c2bf211450e91f01ceadaa9fc97a2b4031"},{"introduced":"7b07c0ccc7453ce057e009ffa65f12a02ce7d2ee"},{"introduced":"ec8826ed50f8ce0eea39900eeeba09a9d621f00e"},{"introduced":"b5f6ca5af6e29fe5df7a65d512b177fa465cfa2e"},{"introduced":"7acf453090c10537e6f41fc4cf2608d7bbcce8ca"},{"introduced":"7c76a1b79e21176b176b5b6d6b03151f8eea4b55"},{"introduced":"efa83f48bd4ebd066e5efc94b9feefe50e7925a2"},{"introduced":"2ac9b801ef5c18accf223b093529dacfcf809133"},{"introduced":"31f7ece8503f0dc6ef1df2473ae3f3d352973e12"},{"introduced":"b3bf6266acd61682bc654845f621b4426645e324"},{"introduced":"5aa596fee9bf6ea7f0ccc2ed51b16c0f2f04076b"},{"introduced":"1cf3888655c0eb8b0b0539834ad67db5920190d7"},{"introduced":"d05f0a86b23e37b9d97acd9317ff3fd661d64dea"},{"introduced":"e0bedd676512ace4c5586337c072037298315f79"},{"introduced":"944a787b8071d3a27f4ac68980c21ed6137db91d"},{"introduced":"96a6969aab5f0b9362cbc984af230bdfc93022e8"},{"introduced":"895d6a691d7ccdfe80cdf999bc0c8a78d11ad55a"},{"introduced":"4b54a6c2c9a3be775cc6dda66ed207998b068c8f"},{"introduced":"b83a8be65054cd890e24c7c1416ebbb39aeb4c09"},{"introduced":"1c0a2efa5eac05dfd3b7d2b9cfe68e02da55b966"},{"introduced":"e33c9f3203961a823ec8410fc1481f6c87b4e3db"},{"introduced":"b829903bb0104bfeccc7623946a25cb7ccda1dea"},{"introduced":"4a6363076129378869f8742ef00a39a7421e6f29"},{"fixed":"e8676f6226fb01cd17222c771717969f42e73505"}],"database_specific":{"cpe":"cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.1"},{"last_affected":"4.1.38"},{"introduced":"4.2"},{"last_affected":"4.2.35"},{"introduced":"4.3"},{"last_affected":"4.3.31"},{"introduced":"4.4"},{"last_affected":"4.4.30"},{"introduced":"4.5"},{"last_affected":"4.5.29"},{"introduced":"4.6"},{"last_affected":"4.6.26"},{"introduced":"4.7"},{"last_affected":"4.7.26"},{"introduced":"4.8"},{"last_affected":"4.8.22"},{"introduced":"4.9"},{"last_affected":"4.9.23"},{"introduced":"5.0"},{"last_affected":"5.0.19"},{"introduced":"5.1"},{"last_affected":"5.1.16"},{"introduced":"5.2"},{"last_affected":"5.2.18"},{"introduced":"5.3"},{"last_affected":"5.3.15"},{"introduced":"5.4"},{"last_affected":"5.4.13"},{"introduced":"5.5"},{"last_affected":"5.5.12"},{"introduced":"5.6"},{"last_affected":"5.6.11"},{"introduced":"5.7"},{"last_affected":"5.7.9"},{"introduced":"5.8"},{"last_affected":"5.8.7"},{"introduced":"5.9"},{"last_affected":"5.9.7"},{"introduced":"6.0"},{"last_affected":"6.0.5"},{"introduced":"6.1"},{"last_affected":"6.1.3"},{"introduced":"6.2"},{"last_affected":"6.2.2"},{"introduced":"6.3"},{"fixed":"6.3.2"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-39999.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}