Untriaged
Permalink
CVE-2023-44150
7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
WordPress ProfilePress Plugin <= 4.13.2 is vulnerable to Sensitive Data Exposure
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This issue affects Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: from n/a through 4.13.2.
References
Affected products
wp-user-avatar
- =<4.13.2
user_registration\,_login_form\,_user_profile_\&_membership
- =<4.13.2
Matching in nixpkgs
-
nixos-unstable -
- nixpkgs-unstable 1.4.1