Sensitive Information Exposure in Moving Users Plugin for WordPress
CVE-2024-12637

5.3MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
17 January 2025

Summary

The Moving Users plugin for WordPress is exposed to a vulnerability that allows the export functionality to store JSON files in predictable locations with easily guessable names. This may enable attackers without authentication to access sensitive user information, such as email addresses, hashed passwords, and IP addresses. Users are advised to review their security measures and update their plugins to secure their data.

Affected Version(s)

Moving Users * <= 1.05

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Emil F
.