Sensitive Information Exposure in Moving Users Plugin for WordPress
CVE-2024-12637
5.3MEDIUM
Summary
The Moving Users plugin for WordPress is exposed to a vulnerability that allows the export functionality to store JSON files in predictable locations with easily guessable names. This may enable attackers without authentication to access sensitive user information, such as email addresses, hashed passwords, and IP addresses. Users are advised to review their security measures and update their plugins to secure their data.
Affected Version(s)
Moving Users * <= 1.05
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Emil F