Information Disclosure Vulnerability in Easy Registration Forms by WordPress
CVE-2023-5134

4.3MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
23 September 2023

Summary

The Easy Registration Forms plugin for WordPress is affected by an information disclosure vulnerability that allows authenticated attackers to expose sensitive user meta information. The vulnerability resides in the 'erforms_user_meta' shortcode, which due to inadequate safeguards, permits users with subscriber-level capabilities or higher to access arbitrary user meta data. This could potentially lead to the unauthorized retrieval of private or sensitive information, emphasizing the need for urgent updates to versions before 2.1.1 to ensure user data confidentiality.

Affected Version(s)

Easy Registration Forms * <= 2.1.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lana Codes
.