The Stream WordPress plugin before 3.9.2 does not prevent users with little privileges on the site (like subscribers) from using its alert creation functionality, which may enable them to leak sensitive information.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-51733 | The Stream WordPress plugin before 3.9.2 does not prevent users with little privileges on the site (like subscribers) from using its alert creation functionality, which may enable them to leak sensitive information. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 25 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-03-25T20:41:44.440Z
Reserved: 2022-12-09T14:57:09.167Z
Link: CVE-2022-4384
Updated: 2024-08-03T01:41:44.451Z
Status : Modified
Published: 2023-02-06T20:15:11.330
Modified: 2025-03-25T21:15:38.660
Link: CVE-2022-4384
No data.
OpenCVE Enrichment
No data.
EUVD