CVE-2023-1371: w4 Post List Project w4 Post List

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which could allow any authenticated users to access them

Affected products

Published 2023-04-17. Last modified 2026-06-17.