4.3
CVE-2024-1279
- EPSS 0.33%
- Veröffentlicht 11.03.2024 18:15:17
- Zuletzt bearbeitet 28.03.2025 19:15:17
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Paid Memberships Pro <= 2.12.8 - Authenticated (Contributor+) Information Disclosure via Shortcode
The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.
Mögliche Gegenmaßnahme
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions: Update to version 2.12.9, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions
Version
*-2.12.8
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Strangerstudios ≫ Paid Memberships Pro SwPlatformwordpress Version < 2.12.9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.554 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|