CVE-2021-24859

CVE-2021-24859

The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes

Source: CVE-2021-24859

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다