The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NStrangerstudios Paid Memberships Pro
APPStrangerstudios< 1.2.6
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2023-23488CRITICAL9.8PL ✓ten sam produkt
SQL Injection w wtyczce Paid Memberships Pro dla WordPress (bez uwierzytelnienia)
CVE-2021-25114CRITICAL9.8PL ✓ten sam produkt
SQL injection w wtyczce Paid Memberships Pro dla WordPress
CVE-2024-37277HIGH7.5ten sam produkt
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functi...
CVE-2024-37486HIGH7.6ten sam produkt
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Mem...
CVE-2023-6187HIGH7.5ten sam produkt
The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file...