CVE-2023-4836

CVE-2023-4836: WordPress File Sharing Plugin < 2.0.5 - Subscriber+ Sensitive Data and Files Exposure via IDOR

Vendor Unknown
Product WordPress File Sharing Plugin
Published October 31, 2023
Last update April 3, 2025

CVSS base score

What the vulnerability does

01Description

The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced

Key dates

02Disclosure timeline

October 31, 2023 CVE published
April 3, 2025 Record updated