The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-07-30 06:15
Updated : 2024-11-21 08:50
NVD link : CVE-2024-1287
Mitre link : CVE-2024-1287
CVE.ORG link : CVE-2024-1287
JSON object : View
Products Affected
No product.
CWE
CWE-202
Exposure of Sensitive Information Through Data Queries