The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes.
References
Configurations
No configuration.
History
01 Aug 2024, 13:46
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
CWE | CWE-202 |
30 Jul 2024, 13:32
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
30 Jul 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-30 06:15
Updated : 2024-08-01 13:46
NVD link : CVE-2024-1287
Mitre link : CVE-2024-1287
CVE.ORG link : CVE-2024-1287
JSON object : View
Products Affected
No product.
CWE
CWE-202
Exposure of Sensitive Information Through Data Queries