The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authenticated users such as subscriber to retrieve arbitrary user meta (except the user_pass), such as the user email and activation key by default.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/35404d16-7213-4293-ac0d-926bd6c17444 | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: WPScan
Published: 2023-03-20T15:52:23.686Z
Updated: 2023-03-28T07:14:03.965Z
Reserved: 2023-02-18T09:44:16.619Z
Link: CVE-2023-0911
JSON object: View
NVD Information
Status : Modified
Published: 2023-03-20T16:15:12.800
Modified: 2023-11-07T04:01:53.230
Link: CVE-2023-0911
JSON object: View
Redhat Information
No data.
CWE