CVE-2024-1286: Paid Memberships Pro - Membership Maps Add On < 0.7 - Contributor+ Sensitive Information Disclosure
Published Jul 30, 2024
·Updated
The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site.
Affected Software
2 affected components
Paid Memberships Pro Membership Maps Add On<0.7
Strangerstudios Paid Memberships Pro Wordpress<0.7
Event History
Jul 30, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityAffected Software
Sep 5, 57630
Event
via NVD·08:33 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-1286?
CVE-2024-1286 has a medium severity rating due to the potential leakage of sensitive user information.
2
How do I fix CVE-2024-1286?
To fix CVE-2024-1286, upgrade the pmpro-membership-maps plugin to version 0.7 or later.
3
What does CVE-2024-1286 affect?
CVE-2024-1286 affects the pmpro-membership-maps WordPress plugin prior to version 0.7.
4
Who is at risk from CVE-2024-1286?
Users with at least the contributor role are at risk of leaking sensitive information about memberships due to CVE-2024-1286.
5
Is CVE-2024-1286 being actively exploited?
There is no current evidence indicating that CVE-2024-1286 is being actively exploited in the wild.