Логотип exploitDog
bind:CVE-2021-24170
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24170

Количество 2

Количество 2

nvd логотип

CVE-2021-24170

почти 5 лет назад

The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-rgpr-gv7f-4cf5

больше 3 лет назад

The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24170

The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

CVSS3: 7.5
29%
Средний
почти 5 лет назад
github логотип
GHSA-rgpr-gv7f-4cf5

The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

29%
Средний
больше 3 лет назад

Уязвимостей на страницу