← Back

Wp Private Messaging

wp_private_messaging

Vendor: Apusthemes • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apusthemes
1Wp Private Messaging
Mar 12, 2025
Feb 21, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any au...Show more
The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID.Show less