CVE-2022-0287

The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog
Configurations

Configuration 1 (hide)

cpe:2.3:a:mycred:mycred:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 06:38

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/6cd7cd6d-1cc1-472c-809b-b66389f149b0 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/6cd7cd6d-1cc1-472c-809b-b66389f149b0 - Exploit, Third Party Advisory

07 Nov 2023, 03:41

Type Values Removed Values Added
CWE CWE-862

24 Jul 2023, 10:15

Type Values Removed Values Added
Summary The myCred WordPress plugin before 2.4.3.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog

21 Jul 2023, 16:53

Type Values Removed Values Added
CWE CWE-200 CWE-862

Information

Published : 2022-04-25 16:16

Updated : 2024-11-21 06:38


NVD link : CVE-2022-0287

Mitre link : CVE-2022-0287

CVE.ORG link : CVE-2022-0287


JSON object : View

Products Affected

mycred

  • mycred
CWE
CWE-862

Missing Authorization