Lucene search

K
wpvulndbWpvulndbWPVDB-ID:031DA4A6-B196-4221-992E-DE96EAF915B0
HistoryOct 12, 2023 - 12:00 a.m.

Profile Extra Fields by BestWebSoft < 1.2.8 - Unauthenticated Sensitive Data Disclosure

2023-10-1200:00:00
wpscan.com
3
profile extra fields
unauthenticated access
sensitive data disclosure

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

24.2%

Description The plugin does not have authorisation in the prflxtrflds_export_file() function, allowing unauthenticated users to retrieve sensitive data such as the ones entered in custom fields

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

24.2%

Related for WPVDB-ID:031DA4A6-B196-4221-992E-DE96EAF915B0