CVE-2024-1279: Paid Memberships Pro < 2.12.9 - Contributor+ Arbitrary User Custom Field Disclosure
Published Mar 11, 2024
·Updated
The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.
Affected Software
2 affected components
Paid Memberships Pro Paid Memberships Pro<2.12.9
Strangerstudios Paid Memberships Pro Wordpress<2.12.9
Event History
Mar 11, 2024
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-1279?
CVE-2024-1279 has a medium severity due to its potential to leak sensitive user metadata.
2
How do I fix CVE-2024-1279?
To mitigate CVE-2024-1279, update the Paid Memberships Pro WordPress plugin to version 2.12.9 or later.
3
Who is affected by CVE-2024-1279?
Users with the contributor role in the Paid Memberships Pro WordPress plugin may exploit CVE-2024-1279 to access other users' sensitive metadata.
4
What versions of Paid Memberships Pro are affected by CVE-2024-1279?
CVE-2024-1279 affects all versions of Paid Memberships Pro before 2.12.9.
5
Is CVE-2024-1279 a local or remote vulnerability?
CVE-2024-1279 is considered a local vulnerability since it requires a contributor-level user to exploit it.