The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NStrangerstudios Paid Memberships Pro
APPStrangerstudios< 1.2.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2023-23488CRITICAL9.8PL ✓same product
SQL Injection w wtyczce Paid Memberships Pro dla WordPress (bez uwierzytelnienia)
CVE-2021-25114CRITICAL9.8PL ✓same product
SQL injection w wtyczce Paid Memberships Pro dla WordPress
CVE-2024-37277HIGH7.5same product
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functi...
CVE-2024-37486HIGH7.6same product
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Mem...
CVE-2023-6187HIGH7.5same product
The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file...