CVE-2023-5561


WordPress < 6.3.2 - Unauthenticated Post Author Email Disclosure

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack



We have discovered 1,079,839 live websites that are affected by CVE-2023-5561.

Contact us to get more info




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Versions
  • from 4.7 before 4.7.27
  • from 4.8 before 4.8.23
  • from 4.9 before 4.9.24
  • from 5 before 5.0.20
  • from 5.2 before 5.2.19
  • from 5.3 before 5.3.16
  • from 5.4 before 5.4.14
  • from 5.5 before 5.5.13
  • from 5.6 before 5.6.12
  • from 5.7 before 5.7.10
  • from 5.8 before 5.8.8
  • from 5.9 before 5.9.8
  • from 6 before 6.0.6
  • from 6.1 before 6.1.4
  • from 6.2 before 6.2.3
  • from 6.3 before 6.3.2
Total Vulnerable Versions780
Vulnerable Domains1,079,839 live websites (9.47% of WordPress install base)


Common Weakness Enumeration


CWE-200 Exposure of Sensitive Information to an Unauthorized Actor


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-5561 and the relative popularity of websites


Details

  • Published - Oct 16, 2023
  • Updated - Nov 8, 2023

Credits

  • Marc Montpas (finder)
  • WPScan (coordinator)





Countries

United States269,771 websites



Germany93,776 websites
GB55,996 websites
Japan53,229 websites
France51,109 websites
Italy46,257 websites
Netherlands40,769 websites
Poland39,036 websites
Russia38,095 websites
Spain31,869 websites

TLDs

.com435,556 websites
.de59,349 websites
.org47,380 websites
.nl33,006 websites
.ru31,861 websites
.co.uk31,803 websites
.net31,534 websites
.it31,040 websites
.pl28,634 websites
.fr20,616 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-5561 through included software libraries and plugins.



References


Websites affected by CVE-2023-5561

Top websites that are affected by CVE-2023-5561. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***************.org United States***
****.******.com Singapore***
***.**********.com United States***
***.*********.com Germany***
***.******.com United States***
***.*********.com United States***
*********.net United States***
**********.ca Canada*,***
************.***.ar Argentina*,***
****.*******.org United States*,***
See full domain list