CVE-2023-5561

MEDIUM5.3EPSS 53.0%

WordPress < 6.3.2 - Unauthenticated Post Author Email Disclosure

Published: 10/16/2023Modified: 5/27/2026

Description

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

Affected packages (3)

  • Bitnami/wordpress>= 4.7.0, < 4.7.27, >= 4.8.0, < 4.8.23, >= 4.9.0, < 4.9.24, >= 5.0.0, < 5.0.20, >= 5.1.0, < 5.1.17, >= 5.2.0, < 5.2.19, >= 5.3.0, < 5.3.16, >= 5.4.0, < 5.4.14, >= 5.5.0, < 5.5.13, >= 5.6.0, < 5.6.12, >= 5.7.0, < 5.7.10, >= 5.8.0, < 5.8.8, >= 5.9.0, < 5.9.8, >= 6.0.0, < 6.0.6, >= 6.1.0, < 6.1.4, >= 6.2.0, < 6.2.3, >= 6.3.0, < 6.3.2
  • Bitnami/wordpress-multisite>= 4.7.0, < 4.7.27, >= 4.8.0, < 4.8.23, >= 4.9.0, < 4.9.24, >= 5.0.0, < 5.0.20, >= 5.1.0, < 5.1.17, >= 5.2.0, < 5.2.19, >= 5.3.0, < 5.3.16, >= 5.4.0, < 5.4.14, >= 5.5.0, < 5.5.13, >= 5.6.0, < 5.6.12, >= 5.7.0, < 5.7.10, >= 5.8.0, < 5.8.8, >= 5.9.0, < 5.9.8, >= 6.0.0, < 6.0.6, >= 6.1.0, < 6.1.4, >= 6.2.0, < 6.2.3, >= 6.3.0, < 6.3.2
  • Debian/wordpressfrom 0, < 5.7.11+dfsg1-0+deb11u1

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References (5)