CVE-2023-3601: Webfactoryltd Simple Author Box

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

The Simple Author Box WordPress plugin before 2.52 does not verify a user ID before outputting information about that user, leading to arbitrary user information disclosure to users with a role as low as Contributor.

Affected products

Published 2023-08-14. Last modified 2026-06-17.