Vulnerability CVE-2024-1564


Published: 2024-03-25

Description:
The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access custom fields on any post regardless of post type or status via a shortcode

 References:
https://wpscan.com/vulnerability/ecb1e36f-9c6e-4754-8878-03c97194644d/

Copyright 2026, cxsecurity.com

 

Back to Top