Known CVE
WordPress Core - Post Author Email Disclosure
WordPress Core is vulnerable to Sensitive Information Exposure in versions between 4.7.0 and 6.3.1 via the User REST endpoint. While the search results do not display user email addresses unless the requesting user has the 'list_users' capability, the search is applied to the user_email column.
CVE-2023-5561
Medium2023CVSS 5.3CWE-200
cve2023 · wpscan · disclosure · wp · wordpress · email · exposure · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website