Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m96c-8jmv-4r54

Опубликовано: 14 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes

The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes

EPSS

Процентиль: 40%
0.00186
Низкий

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.3
nvd
около 4 лет назад

The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes

EPSS

Процентиль: 40%
0.00186
Низкий

Дефекты

CWE-284