Information Disclosure Vulnerability in Easy Registration Forms by WordPress
CVE-2023-5134
4.3MEDIUM
Summary
The Easy Registration Forms plugin for WordPress is affected by an information disclosure vulnerability that allows authenticated attackers to expose sensitive user meta information. The vulnerability resides in the 'erforms_user_meta' shortcode, which due to inadequate safeguards, permits users with subscriber-level capabilities or higher to access arbitrary user meta data. This could potentially lead to the unauthorized retrieval of private or sensitive information, emphasizing the need for urgent updates to versions before 2.1.1 to ensure user data confidentiality.
Affected Version(s)
Easy Registration Forms * <= 2.1.1
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lana Codes