Sensitive Information Disclosure in UserPro WordPress Plugin
CVE-2023-2446
6.5MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 22 November 2023
Summary
The UserPro plugin for WordPress has a vulnerability that permits authenticated attackers with subscriber-level access to exploit the 'userpro' shortcode, leading to the unintended disclosure of sensitive user meta values. This exposure arises from inadequate restrictions imposed on these values, potentially enabling adversaries to obtain critical user information that could facilitate unauthorized access to higher-privileged accounts. Users should update to the latest version to mitigate potential risks.
Affected Version(s)
UserPro - Community and User Profile WordPress Plugin * <= 5.1.1
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
István Márton