Lucene search

K
wpvulndbWpvulndbWPVDB-ID:1A82792F-EE0A-4EB0-AFE5-67C7C6F99A43
HistoryJan 18, 2024 - 12:00 a.m.

Profile Builder Pro < 3.10.1 - Authenticated (Subscriber+) Time-Based One-Time Password Sensitive Information Exposure

2024-01-1800:00:00
wpscan.com
3
wordpress
vulnerable
sensitive information
authenticated
subscriber level

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

37.4%

Description The Profile Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.10.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract a sensitive time-based one-time password (TOTP).

CPENameOperatorVersion
eq3.10.1

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

37.4%

Related for WPVDB-ID:1A82792F-EE0A-4EB0-AFE5-67C7C6F99A43