The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.8 via the download_user_ajax function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including usernames, hashed passwords, and emails.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Sep 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpextended
Wpextended wp Extended |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:wpextended:wp_extended:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpextended
Wpextended wp Extended |
Wed, 04 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 04 Sep 2024 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.8 via the download_user_ajax function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including usernames, hashed passwords, and emails. | |
Title | The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Authenticated (Subscriber+) Sensitive Information Exposure | |
Weaknesses | CWE-200 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-09-04T06:49:04.798Z
Updated: 2024-09-04T14:13:01.800Z
Reserved: 2024-08-22T20:02:27.093Z
Link: CVE-2024-8106
Vulnrichment
Updated: 2024-09-04T14:12:56.249Z
NVD
Status : Analyzed
Published: 2024-09-04T07:15:04.180
Modified: 2024-09-05T13:05:52.540
Link: CVE-2024-8106
Redhat
No data.