CyberRota Analysis
AI-GeneratedThe My Private Site plugin for WordPress prior to version 4.2.3 is vulnerable as it fails to enforce site-privacy access controls on specific unauthenticated front-end areas, enabling unauthorized users to access post content, comments, and URLs intended for logged-in users only. This exposure could lead to unauthorized information disclosure, compromising the privacy of site content. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.
Original NVD Description
The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site the administrator placed behind mandatory login.