First published: Mon Mar 11 2024(Updated: )
The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paid Memberships Pro | <2.12.9 | |
Paid Memberships Pro | <2.12.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1279 has a medium severity due to its potential to leak sensitive user metadata.
To mitigate CVE-2024-1279, update the Paid Memberships Pro WordPress plugin to version 2.12.9 or later.
Users with the contributor role in the Paid Memberships Pro WordPress plugin may exploit CVE-2024-1279 to access other users' sensitive metadata.
CVE-2024-1279 affects all versions of Paid Memberships Pro before 2.12.9.
CVE-2024-1279 is considered a local vulnerability since it requires a contributor-level user to exploit it.