The WP Show Posts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with subscriber access and above, to view arbitrary post metadata, list posts, and view terms and taxonomies.
We have discovered 7,064 live websites that are affected by CVE-2023-6731.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 7,064 live websites (21% of Wp Show Posts install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 5 versions ( 71% of all versions) |
| 2,139 websites | |
| 891 websites | |
| 576 websites | |
| 436 websites | |
| 387 websites | |
| 353 websites | |
| 346 websites | |
| 169 websites | |
| 167 websites | |
| 131 websites |
| .com | 3,109 websites |
| .org | 551 websites |
| .com.au | 345 websites |
| .net | 277 websites |
| .de | 243 websites |
| .jp | 194 websites |
| .es | 172 websites |
| .fr | 141 websites |
| .co.jp | 133 websites |
| .it | 125 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********************.com | *,*** | ||
| ******.net | **,*** | ||
| **************.com | **,*** | ||
| ********************.com | **,*** | ||
| *****************.com | ***,*** | ||
| **********.cl | ***,*** | ||
| *************.jp | ***,*** | ||
| **********.com | ***,*** | ||
| ********.com | ***,*** | ||
| ******.com | ***,*** |
FAQ