Vulnerabilities (CVE)

Filtered by vendor User Meta Shortcodes Project Subscribe
Filtered by product User Meta Shortcodes
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24859 1 User Meta Shortcodes Project 1 User Meta Shortcodes 2024-02-28 4.0 MEDIUM 4.3 MEDIUM
The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes