Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-0556

19
FAUCET Score

CVE-2023-0556 describes an authorization bypass vulnerability in the ContentStudio plugin for WordPress, affecting versions up to and including 1.2.5. Unauthenticated attackers can exploit a missing capability check to retrieve blog metadata, including the plugin's contentstudio_token. This token can then be used to interact with the plugin, potentially creating posts in older versions. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring no user interaction, and resulting in low confidentiality and integrity impacts. While the EPSS score is low, suggesting a lower likelihood of exploitation, the FAUCET Risk Score is 40/100. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for the vast majority of reported vulnerabilities.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.2.6CPE matchmatch criteria
cpe:2.3:a:contentstudio:contentstudio:*:*:*:*:*:wordpress:*:*
>= 0, <= 1.2.5CPE match
cpe:2.3:a:contentstudio:contentstudio:*:*:*:*:*:wordpress:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.95%
Probability of exploitation in next 30 days
EPSS Percentile
57.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0095 is in the 36th percentile among its peer group of 23,703 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

wordfence.com / threat-intel/vulnerabilities/id/52db8d41-859a-4d68-8b83-3d3af8f1bf64
Third Party Advisory
plugins.trac.wordpress.org / browser/contentstudio/tags/1.2.1/contentstudio-plugin.php
ExploitThird Party Advisory
plugins.trac.wordpress.org / changeset
PatchThird Party Advisory
wordfence.com / threat-intel/vulnerabilities/id/52db8d41-859a-4d68-8b83-3d3af8f1bf64