CVE-2023-5692: WordPress Foundation WordPress
Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.
WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to expose the slug of a custom post whose 'publicly_queryable' post status has been set to 'false'.
Affected products
- WordPress Foundation WordPress: up to and including 6.4.3
Published 2024-04-05. Last modified 2026-06-17.