The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.
History

Fri, 22 Aug 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Paidmembershipspro
Paidmembershipspro paid Memberships Pro
CPEs cpe:2.3:a:paidmembershipspro:paid_memberships_pro:*:*:*:*:*:*:*:*
Vendors & Products Paidmembershipspro
Paidmembershipspro paid Memberships Pro
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 22 Aug 2025 08:45:00 +0000

Type Values Removed Values Added
Description The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes. The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.
Title Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure and SQLi Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00082}

epss

{'score': 0.00088}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00079}

epss

{'score': 0.00082}


Thu, 10 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Strangerstudios
Strangerstudios paid Memberships Pro
CPEs cpe:2.3:a:strangerstudios:paid_memberships_pro:*:*:*:*:*:wordpress:*:*
Vendors & Products Strangerstudios
Strangerstudios paid Memberships Pro

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-08-27T12:00:38.906Z

Reserved: 2024-02-06T19:17:34.488Z

Link: CVE-2024-1287

cve-icon Vulnrichment

Updated: 2024-08-01T18:33:25.572Z

cve-icon NVD

Status : Modified

Published: 2024-07-30T06:15:02.210

Modified: 2025-08-22T09:15:32.390

Link: CVE-2024-1287

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.