Description
WordPress Plugin WP Private Message is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to read arbitrary messages. WordPress Plugin WP Private Message version 1.0.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.6 or latest
References
Related Vulnerabilities
WordPress Plugin WooCommerce Dynamic Pricing & Discounts Multiple Vulnerabilities (2.4.1)
GlassFish Improper Input Validation Vulnerability (CVE-2011-5035)
Oracle Database Server CVE-2006-1877 Vulnerability (CVE-2006-1877)
SharePoint CVE-2019-1035 Vulnerability (CVE-2019-1035)
Liferay Portal Missing Authorization Vulnerability (CVE-2023-3426)