The Blocksy Companion WordPress plugin prior to 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
creativethemes blocksy companion |