CVE-2022-0287: Mycred < 2.4.4.1 - Subscriber+ User E-mail Addresses Disclosure
Published Apr 25, 2022
·Updated
The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog
Affected Software
2 affected components
Mycred myCred WordPress<2.4.4.1
Wpexperts Mycred Wordpress<2.4.4.1
Event History
Apr 25, 2022
CVE Published
via MITRE·03:50 PM
Data Sourced
via MITRE·03:50 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-0287?
The severity of CVE-2022-0287 is medium with a severity value of 4.3.
2
How does CVE-2022-0287 affect myCred WordPress plugin?
CVE-2022-0287 affects myCred WordPress plugin versions up to and including 2.4.4.1.
3
What is the vulnerability description of CVE-2022-0287?
CVE-2022-0287 is a vulnerability in the mycred-tools-select-user AJAX action of myCred WordPress plugin which allows any authenticated user to retrieve all email addresses from the blog.
4
Is CVE-2022-0287 a common weakness enumeration (CWE) vulnerability?
Yes, CVE-2022-0287 is categorized as CWE-862.
5
How do I fix CVE-2022-0287?
To fix CVE-2022-0287, update the myCred WordPress plugin to version 2.4.4.2 or later.