User meta shortcodes <= 0.5 - Improper Access Control
mediumThe User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashes
- CVSS:
- 4.3
- Affected:
- up to 0.5
- Fix:
- No patched version reported
- Disclosed:
- Nov 15, 2021