7.5
CVE-2024-6477
- EPSS 0.3%
- Veröffentlicht 03.08.2024 06:16:29
- Zuletzt bearbeitet 22.08.2025 09:15:33
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP <= 1.2.11 - Unauthenticated Information Disclosure via Unprotected Directories
The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive information such as IP, username, and email address
Mögliche Gegenmaßnahme
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: Update to version 1.2.12, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
Version
* - 1.2.11
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.531 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|