Low
CVSS 3.7
Overview
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private a...
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.
This vulnerability is rated 🟢 LOW.
Recommended actions: