CVE-2023-39999
Executive Summary
CVE-2023-39999 exposes sensitive information to unauthorized actors in WordPress across versions 4.1 through 6.3.1, affecting a wide range of releases. The vulnerability allows attackers to retrieve confidential data, potentially compromising site integrity and user privacy. Immediate patching or upgrading to a fixed version is recommended to mitigate data exposure risks.
Authoritative CVE Metadata - CVSS Base Score: 4.3 (MEDIUM) - Published: 2023-10-13T12:15:09.970 - Last Modified: 2026-10-05T13:16:48.530
Original Description: Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38.
"It is through science that we prove, but through intuition that we discover."
— Jules Poincare