The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Aug 2025 09:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Paidmembershipspro
Paidmembershipspro paid Memberships Pro |
|
CPEs | cpe:2.3:a:paidmembershipspro:paid_memberships_pro:*:*:*:*:*:*:*:* | |
Vendors & Products |
Paidmembershipspro
Paidmembershipspro paid Memberships Pro |
|
Metrics |
ssvc
|
Fri, 22 Aug 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes. | The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector. |
Title | Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure and SQLi | Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi |
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Thu, 10 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Strangerstudios
Strangerstudios paid Memberships Pro |
|
CPEs | cpe:2.3:a:strangerstudios:paid_memberships_pro:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Strangerstudios
Strangerstudios paid Memberships Pro |

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-08-27T12:00:38.906Z
Reserved: 2024-02-06T19:17:34.488Z
Link: CVE-2024-1287

Updated: 2024-08-01T18:33:25.572Z

Status : Modified
Published: 2024-07-30T06:15:02.210
Modified: 2025-08-22T09:15:32.390
Link: CVE-2024-1287

No data.

No data.