The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including user emails, password hashes, usernames, and more.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Oct 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Butlerblog
Butlerblog wp-members |
|
CPEs | cpe:2.3:a:butlerblog:wp-members:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wp-members Project
Wp-members Project wp-members |
Butlerblog
Butlerblog wp-members |
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-01-04T03:30:12.554Z
Updated: 2024-08-02T08:35:14.905Z
Reserved: 2023-12-12T15:18:41.225Z
Link: CVE-2023-6733
Vulnrichment
No data.
NVD
Status : Modified
Published: 2024-01-04T04:15:09.550
Modified: 2024-11-21T08:44:26.820
Link: CVE-2023-6733
Redhat
No data.