CVE-2023-5692
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedWordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to expose the slug of a custom post whose 'publicly_queryable' post status has been set to 'false'.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceWordPress Core contains a sensitive information exposure vulnerability in the redirect_guess_404_permalink function. Unauthenticated attackers can exploit this to discover the slugs of custom posts that have publicly_queryable set to false in their post status, revealing hidden content paths that should not be accessible.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- Low
- Integrity
- None
- Availability
- None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Check your WordPress Core versionAccess your site via FTP or file manager and open the wp-includes/version.php file. Look for the $wp_version variable. Alternatively, check the readme.html file in the WordPress root directory.Affected if The installed version is lower than 6.4.3 (the patched version)
-
Identify custom post types with restricted visibilitySearch your theme and plugin files for register_post_type calls. Look for arguments where publicly_queryable is set to false. You can also check the database wp_posts table for post types that may not be publicly visible.Affected if Your site has custom post types registered with publicly_queryable set to false
-
Verify the redirect_404_permalink function existsInspect the wp-includes/functions.php file (or canonical.php in newer versions) to confirm the redirect_guess_404_permalink function is present in your WordPress installation.Affected if The function exists and handles 404 requests in your environment
-
Test if 404 pages expose hidden post slugsSend a request to a non-existent URL on your site such as /nonexistent-page-12345. Observe if the response redirects or suggests valid post slugs that should not be publicly known, especially for posts with publicly_queryable=false post types.Affected if The server response reveals hidden or private post slugs that were not intentionally made public
-
Review server access logs for vulnerability probesExamine your web server access logs for requests to non-existent pages followed by requests using discovered slug patterns. Look for repeated 404 requests that eventually succeed with hidden content paths.Affected if Logs show patterns of attackers discovering and accessing previously hidden content URLs
Your site is affected if it runs WordPress Core versions earlier than 6.4.3 AND has custom post types with publicly_queryable set to false that could have their hidden slugs exposed through 404 handling.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scopedUpdate WordPress to version 6.4.3 or later to patch this vulnerability. As this affects the core, no custom code changes are required beyond the standard WordPress update process.
Latest stable WordPress release (6.5 or higher)
- Log in to your WordPress admin dashboard
- Navigate to Dashboard > Updates or go to /wp-admin/update-core.php
- Click 'Update Now' to upgrade to the latest stable WordPress version
- Alternatively, manually download the latest WordPress release from wordpress.org and replace core files via FTP or hosting control panel
- After upgrading, verify the version number matches the latest stable release which contains the security fix
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation1.0 h
- Implementation1.0 h
- Testing2.0 h
- Review / QA1.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $1,376.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2023-5692 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2023-5692 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data