
Restrict Content <= 3.2.7 - 레거시 로그 파일을 통한 정보 노출
Restrict Content <= 3.2.7 - 레거시 로그 파일을 통한 정보 노출
WordPress용 회원제 플러그인 – Restrict Content 플러그인은 레거시 로그 파일을 통해 3.2.7 이하의 모든 버전에서 민감 정보 노출에 취약합니다. 이를 통해 인증되지 않은 공격자가 디버그 정보를 포함한 민감한 데이터를 추출할 수 있습니다.
Severity: medium
CVE ID: CVE-2023-47668
CVSS Score: 5.3
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Plugin Slug: restrict-content
WPScan URL: https://www.wpscan.com/plugin/restrict-content
Reference URL: https://www.wordfence.com/threat-intel/vulnerabilities/id/ad2d5070-ddc6-4478-abe5-776e197a4507?source=api-prod
/wp-content/uploads/rcp-debug.log