The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive information such as IP, username, and email address
                
            References
                    | Link | Resource | 
|---|---|
| https://wpscan.com/vulnerability/346c855a-4d42-4a87-aac9-e5bfc2242b16/ | Exploit Third Party Advisory | 
Configurations
                    History
                    22 Aug 2025, 09:15
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | (en) The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive information such as IP, username, and email address | 
06 Jun 2025, 16:12
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:ayecode:userswp:*:*:*:*:*:wordpress:*:* | |
| First Time | Ayecode userswp Ayecode | |
| CWE | NVD-CWE-noinfo | |
| References | () https://wpscan.com/vulnerability/346c855a-4d42-4a87-aac9-e5bfc2242b16/ - Exploit, Third Party Advisory | 
Information
                Published : 2024-08-03 06:16
Updated : 2025-08-22 09:15
NVD link : CVE-2024-6477
Mitre link : CVE-2024-6477
CVE.ORG link : CVE-2024-6477
JSON object : View
Products Affected
                ayecode
- userswp
CWE
                