PoC Index

CVE-2024-1287

MEDIUM 6.5EPSS 0.5%

The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.52% chance of exploitation in the next 30 days, 42th percentile
Published
2024-07-30
Updated
2025-08-27

Proof-of-concept exploits (1)

References

Related