The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-07-30T06:00:06.053Z
Updated: 2024-08-01T18:33:25.572Z
Reserved: 2024-02-06T19:17:34.488Z
Link: CVE-2024-1287
Vulnrichment
Updated: 2024-08-01T18:33:25.572Z
NVD
Status : Awaiting Analysis
Published: 2024-07-30T06:15:02.210
Modified: 2024-08-01T13:46:03.523
Link: CVE-2024-1287
Redhat
No data.