Description
WordPress Plugin WP Private Message is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to read arbitrary messages. WordPress Plugin WP Private Message version 1.0.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.6 or latest
References
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3180)
Oracle Application Server CVE-2006-0291 Vulnerability (CVE-2006-0291)
Oracle HTTP Server Other Vulnerability (CVE-2002-0659)
WordPress Plugin MPL-Publisher-Create your Ebook & Audiobook Cross-Site Scripting (1.30.2)