CVE-2024-1279
Paid Memberships Pro < 2.12.9 - Contributor+ Arbitrary User Custom Field Disclosure
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
11 Mar 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
Unknown · Paid Memberships Pro