MEDIUM🇬🇧 English

CVE-2024-1287

CVSS 6.5v3.1pub. 2024-07-30upd. 2025-08-22

The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • Strangerstudios Paid Memberships Pro

    APP
    Strangerstudios
    < 1.2.6
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2023-23488CRITICAL9.8PL ✓ten sam produkt

SQL Injection w wtyczce Paid Memberships Pro dla WordPress (bez uwierzytelnienia)

CVE-2021-25114CRITICAL9.8PL ✓ten sam produkt

SQL injection w wtyczce Paid Memberships Pro dla WordPress

CVE-2024-37277HIGH7.5ten sam produkt

Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functi...

CVE-2024-37486HIGH7.6ten sam produkt

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Mem...

CVE-2023-6187HIGH7.5ten sam produkt

The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file...