ZeroHour

CVE-2023-2623

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p53
Published
()
Modified
Description

The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users

Vendors
iqonic
Products
kivicare
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.