Description
Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module," which allows remote authenticated users with the "Access the content overview page" permission to read all published nodes by accessing the admin/content page.
Remediation
References
Related Vulnerabilities
WordPress Plugin EmbedSocial-Social Media Feeds, Reviews and Galleries Cross-Site Scripting (1.1.27)
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.10)
WordPress Plugin Daily Prayer Time Cross-Site Request Forgery (2023.03.08)
WordPress Plugin Welcart e-Commerce Multiple Vulnerabilities (1.8.2)
WordPress Plugin YITH WooCommerce Product Add-Ons Multiple Vulnerabilities (2.0.7)