The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-07-30T06:00:06.053Z

Updated: 2024-08-01T18:33:25.572Z

Reserved: 2024-02-06T19:17:34.488Z

Link: CVE-2024-1287

cve-icon Vulnrichment

Updated: 2024-08-01T18:33:25.572Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-30T06:15:02.210

Modified: 2024-08-01T13:46:03.523

Link: CVE-2024-1287

cve-icon Redhat

No data.