ZeroHour

CVE-2024-1287

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p43
Published
()
Modified
Description

The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.

Vendors
strangerstudios
Products
paid memberships pro
Ecosystems
WordPress
Weakness
CWE-202
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.