← Back

Squaretype

squaretype

Vendor: Codesupply • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Codesupply
1Squaretype
Nov 21, 2024
Nov 8, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and sc...Show more
The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of its REST endpoint, without any validation. As a result, private and scheduled posts could be retrieved via a crafted request.Show less