Cyber Resilience

CVE-2023-5561

Wordpress 4.7 – 4.7.27

Public PoC
Published
16 October 2023
Modified
23 April 2025
CVSS Score v3.1 5.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score 0.039 89th percentile
Risk Priority 70 floored blend · peak EPSS

Summary

CVE-2023-5561 is a medium-severity an unspecified weakness vulnerability in Wordpress Wordpress. Its CVSS base score is 5.3 (Medium).

Operationally, ranked in the top 11% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

WordPress contains an information disclosure vulnerability because it does not properly restrict which user fields are searchable through the REST API. The flaw affects sites running versions prior to the 6.3.2 release and enables queries against user data associated with public posts.

Unauthenticated attackers can issue crafted REST API requests that function as an oracle, allowing them to enumerate and confirm the email addresses of any users who have published public posts. The attack requires no authentication or user interaction and results only in limited confidentiality impact, reflected in the CVSS 5.3 score.

Advisories from Debian and WPScan indicate that the issue was resolved in WordPress 6.3.2; site administrators are advised to apply the update promptly. Corresponding Debian LTS packages were also released to address the vulnerability in supported distributions.

The CVE carries an EPSS score that reached a peak of 0.6487 before settling at the current value of 0.5302.

EU & UK References

Vulnerability Data

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack

CWE(s)

Related Threats

CVEs Like This One

CVE-2026-60137Same product: Wordpress Wordpress
CVE-2023-22622Same product: Wordpress Wordpress
CVE-2024-4439Same product: Wordpress Wordpress
CVE-2024-31211Same product: Wordpress Wordpress
CVE-2026-63030Same product: Wordpress Wordpress
CVE-2023-2745Same product: Wordpress Wordpress
CVE-2024-31210Same product: Wordpress Wordpress
CVE-2023-38000Same product: Wordpress Wordpress
CVE-2023-39999Same product: Wordpress Wordpress
CVE-2018-12895Same product: Wordpress Wordpress

Affected Assets

wordpress
wordpress
4.7 — 4.7.27 · 4.8 — 4.8.23 · 4.9 — 4.9.24

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References