Information ExposureWeakness · CWE-200

CVE-2023-5692

MEDIUM · 5.3 CVSS v3.1 Published 2024-04-05
Mitigation only
No fix yet — a mitigation exists. There is no fixed release. A documented workaround reduces exposure in the meantime.
See remediation →
62/100
Remediation priority · Elevated
Remotely reachable No privileges Zero-click

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
WordPress Core is vulnerable to Sensitive Information Exposure in versions up to, and including, 6.4.3 via the redirect_guess_404_permalink function. This can allow unauthenticated attackers to expose the slug of a custom post whose 'publicly_queryable' post status has been set to 'false'.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

WordPress Core contains a sensitive information exposure vulnerability in the redirect_guess_404_permalink function. Unauthenticated attackers can exploit this to discover the slugs of custom posts that have publicly_queryable set to false in their post status, revealing hidden content paths that should not be accessible.

MitigationUpdate WordPress to version 6.4.3 or later to patch this vulnerability. As this affects the core, no custom code changes are required beyond the standard WordPress update process.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Check your WordPress Core version
    Access your site via FTP or file manager and open the wp-includes/version.php file. Look for the $wp_version variable. Alternatively, check the readme.html file in the WordPress root directory.
    Affected if The installed version is lower than 6.4.3 (the patched version)
  2. Identify custom post types with restricted visibility
    Search your theme and plugin files for register_post_type calls. Look for arguments where publicly_queryable is set to false. You can also check the database wp_posts table for post types that may not be publicly visible.
    Affected if Your site has custom post types registered with publicly_queryable set to false
  3. Verify the redirect_404_permalink function exists
    Inspect the wp-includes/functions.php file (or canonical.php in newer versions) to confirm the redirect_guess_404_permalink function is present in your WordPress installation.
    Affected if The function exists and handles 404 requests in your environment
  4. Test if 404 pages expose hidden post slugs
    Send a request to a non-existent URL on your site such as /nonexistent-page-12345. Observe if the response redirects or suggests valid post slugs that should not be publicly known, especially for posts with publicly_queryable=false post types.
    Affected if The server response reveals hidden or private post slugs that were not intentionally made public
  5. Review server access logs for vulnerability probes
    Examine your web server access logs for requests to non-existent pages followed by requests using discovered slug patterns. Look for repeated 404 requests that eventually succeed with hidden content paths.
    Affected if Logs show patterns of attackers discovering and accessing previously hidden content URLs

Your site is affected if it runs WordPress Core versions earlier than 6.4.3 AND has custom post types with publicly_queryable set to false that could have their hidden slugs exposed through 404 handling.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Mitigation available No clean upgrade yet — mitigate in the meantime
Mitigation

Update WordPress to version 6.4.3 or later to patch this vulnerability. As this affects the core, no custom code changes are required beyond the standard WordPress update process.

Recommended fix Moderate confidence

Latest stable WordPress release (6.5 or higher)

  1. Log in to your WordPress admin dashboard
  2. Navigate to Dashboard > Updates or go to /wp-admin/update-core.php
  3. Click 'Update Now' to upgrade to the latest stable WordPress version
  4. Alternatively, manually download the latest WordPress release from wordpress.org and replace core files via FTP or hosting control panel
  5. After upgrading, verify the version number matches the latest stable release which contains the security fix
Caveat Standard WordPress minor upgrades typically have low risk, but always backup your site before updating

Generated from the published advisory — verify against the referenced sources before acting.

Have this fixed Scoped from the published advisory
  • Consultation1.0 h
  • Implementation1.0 h
  • Testing2.0 h
  • Review / QA1.0 h
5.0 hours of engineering $860
Get help mitigating

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $1,376.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2023-5692 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2023-5692 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data