PoC Index

CVE-2024-6477

HIGH 7.5EPSS 0.6%

The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive information such as IP, username, and email address

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.57% chance of exploitation in the next 30 days, 45th percentile
Published
2024-08-03
Updated
2025-08-27

Proof-of-concept exploits (1)

References

Related