CVE-2024-1287

The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.
Configurations

Configuration 1 (hide)

cpe:2.3:a:strangerstudios:paid_memberships_pro:*:*:*:*:*:wordpress:*:*

History

22 Aug 2025, 09:15

Type Values Removed Values Added
Summary (en) The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes. (en) The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.

10 Jul 2025, 15:56

Type Values Removed Values Added
CPE cpe:2.3:a:strangerstudios:paid_memberships_pro:*:*:*:*:*:wordpress:*:*
First Time Strangerstudios
Strangerstudios paid Memberships Pro
References () https://wpscan.com/vulnerability/169e5756-4e12-4add-82e9-47471c30f08c/ - () https://wpscan.com/vulnerability/169e5756-4e12-4add-82e9-47471c30f08c/ - Exploit, Third Party Advisory

21 Nov 2024, 08:50

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/169e5756-4e12-4add-82e9-47471c30f08c/ - () https://wpscan.com/vulnerability/169e5756-4e12-4add-82e9-47471c30f08c/ -

01 Aug 2024, 13:46

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-202

30 Jul 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) El complemento de WordPress pmpro-member-directory anterior a 1.2.6 no impide que los usuarios con al menos el rol de colaborador filtren información confidencial de otros usuarios, incluidos los hashes de contraseñas.

30 Jul 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-30 06:15

Updated : 2025-08-22 09:15


NVD link : CVE-2024-1287

Mitre link : CVE-2024-1287

CVE.ORG link : CVE-2024-1287


JSON object : View

Products Affected

strangerstudios

  • paid_memberships_pro
CWE
CWE-202

Exposure of Sensitive Information Through Data Queries