CVE-2024-1287: Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi
Published Jul 30, 2024
·Updated
The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.
Affected Software
3 affected components
Paid Memberships Pro Member Directory Add On<1.2.6
Paid Memberships Pro pmpro-member-directory<1.2.6
Strangerstudios Paid Memberships Pro Wordpress<1.2.6
Event History
Jul 30, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-1287?
CVE-2024-1287 is considered a medium severity vulnerability due to the potential exposure of sensitive user information.
2
How do I fix CVE-2024-1287?
To address CVE-2024-1287, upgrade the pmpro-member-directory WordPress plugin to version 1.2.6 or later.
3
What kind of sensitive information is exposed by CVE-2024-1287?
CVE-2024-1287 can lead to the leakage of sensitive information such as user password hashes.
4
Who is affected by CVE-2024-1287?
Users with at least the contributor role in WordPress are affected by CVE-2024-1287.
5
Is there a workaround for CVE-2024-1287 until a fix is applied?
Currently, there are no well-documented workarounds for CVE-2024-1287 other than upgrading the plugin.