CVE-2020-13764: Infoleak
common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because userpass is not considered a special case for a $currentuser->get($property) call.
Other sources
common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because userpass is not considered a special case for a $currentuser->get($property) call.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13764?
CVE-2020-13764 is rated as a high severity vulnerability due to its potential to leak hashed passwords.
How do I fix CVE-2020-13764?
The fix for CVE-2020-13764 is to update the Gravity Forms plugin to version 2.4.9 or later.
Which versions of Gravity Forms are affected by CVE-2020-13764?
CVE-2020-13764 affects all Gravity Forms plugin versions prior to 2.4.9.
What are the potential consequences of CVE-2020-13764?
If exploited, CVE-2020-13764 can lead to unauthorized access to a user's hashed password, which may compromise user accounts.
Is there any other mitigation for CVE-2020-13764 besides updating?
The primary mitigation for CVE-2020-13764 is updating to the patched version, as there are no known alternative mitigation strategies.