plugin

Pmpro Member Directory Vulnerabilities

2 known security issues reported for the Pmpro Member Directory WordPress plugin. Most recent disclosed Jul 30, 2024.

1 medium

Running Pmpro Member Directory on your site? Check whether your installed version is affected.

Scan your site free

Member Directory [pmpro-member-directory] < 1.2.6

unknown

[en] The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes.

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Jul 30, 2024

CVE-2024-1287 on NVD →

Paid Memberships Pro - Member Directory Add On < 1.2.6 - Authenticated (Contributor+) Information Exposure

medium

The Paid Memberships Pro - Member Directory Add On plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 1.2.6 (exclusive) through the 'pmpro_member_directory' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitiv...

CVSS:
4.3
Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Jul 9, 2024

CVE-2024-1287 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database