Acumbamail < 1.0.4.1 - Sensitive Information Disclosure
highThe Acumbamail plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.0.4 via the callAPI function. This can allow unauthenticated attackers to extract sensitive data including emails, passwords, usernames, etc.
- CVSS:
- 7.5
- Affected:
- up to 1.0.4.1
- Fixed in:
- 1.0.4.1
- Disclosed:
- Apr 30, 2014