ZeroHour

CVE-2022-1186

CVSS 3.1
5.3 medium
EPSS
1%p66
Published
()
Modified
Description

The WordPress plugin Be POPIA Compliant exposed sensitive information to unauthenticated users consisting of site visitors emails and usernames via an API route, in versions up to an including 1.1.5.

Vendors
web-x
Products
be popia compliant
Ecosystems
WordPress
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.