Описание
The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive information such as IP, username, and email address
Ссылки
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.12 (исключая)
cpe:2.3:a:ayecode:userswp:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 61%
0.00412
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 7.5
github
больше 1 года назад
The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive information such as IP, username, and email address
EPSS
Процентиль: 61%
0.00412
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo