4.3

CVE-2024-1279

Exploit

Paid Memberships Pro < 2.12.9 - Contributor+ Arbitrary User Custom Field Disclosure

Paid Memberships Pro <= 2.12.8 - Authenticated (Contributor+) Information Disclosure via Shortcode

The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.
Mögliche Gegenmaßnahme
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: Update to version 2.12.9, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
StrangerstudiosPaid Memberships Pro SwPlatformwordpress Version < 2.12.9
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions
Version *-2.12.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.55% 0.415
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/4c537264-0c23-428e-9a11-7a9e74fb6b69/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/bd5d212e-c672-4fa8-afe7-baeac06e2e7d
Third Party Advisory