CVE-2024-1287

The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.
Configurations

Configuration 1 (hide)

cpe:2.3:a:strangerstudios:paid_memberships_pro:*:*:*:*:*:wordpress:*:*

History

22 Aug 2025, 09:15

Type Values Removed Values Added
Summary (en) The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes. (en) The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.

10 Jul 2025, 15:56

Type Values Removed Values Added
CPE cpe:2.3:a:strangerstudios:paid_memberships_pro:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/169e5756-4e12-4add-82e9-47471c30f08c/ - () https://wpscan.com/vulnerability/169e5756-4e12-4add-82e9-47471c30f08c/ - Exploit, Third Party Advisory
First Time Strangerstudios paid Memberships Pro
Strangerstudios

Information

Published : 2024-07-30 06:15

Updated : 2025-08-22 09:15


NVD link : CVE-2024-1287

Mitre link : CVE-2024-1287

CVE.ORG link : CVE-2024-1287


JSON object : View

Products Affected

strangerstudios

  • paid_memberships_pro
CWE
CWE-202

Exposure of Sensitive Information Through Data Queries