The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes.
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00082}

epss

{'score': 0.00088}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00079}

epss

{'score': 0.00082}


Thu, 10 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Strangerstudios
Strangerstudios paid Memberships Pro
CPEs cpe:2.3:a:strangerstudios:paid_memberships_pro:*:*:*:*:*:wordpress:*:*
Vendors & Products Strangerstudios
Strangerstudios paid Memberships Pro

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-07-30T06:00:06.053Z

Updated: 2024-08-01T18:33:25.572Z

Reserved: 2024-02-06T19:17:34.488Z

Link: CVE-2024-1287

cve-icon Vulnrichment

Updated: 2024-08-01T18:33:25.572Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-30T06:15:02.210

Modified: 2025-07-10T15:56:30.353

Link: CVE-2024-1287

cve-icon Redhat

No data.