CVE-2024-1287

The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes.
Configurations

No configuration.

History

21 Nov 2024, 08:50

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/169e5756-4e12-4add-82e9-47471c30f08c/ - () https://wpscan.com/vulnerability/169e5756-4e12-4add-82e9-47471c30f08c/ -

01 Aug 2024, 13:46

Type Values Removed Values Added
CWE CWE-202
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

30 Jul 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) El complemento de WordPress pmpro-member-directory anterior a 1.2.6 no impide que los usuarios con al menos el rol de colaborador filtren información confidencial de otros usuarios, incluidos los hashes de contraseñas.

30 Jul 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-30 06:15

Updated : 2024-11-21 08:50


NVD link : CVE-2024-1287

Mitre link : CVE-2024-1287

CVE.ORG link : CVE-2024-1287


JSON object : View

Products Affected

No product.

CWE
CWE-202

Exposure of Sensitive Information Through Data Queries