CVE-2024-12637

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 17, 2025
CWE ID 200

Summary

CVE-2024-12637: The WordPress plugin "Moving Users" with versions up to 1.05 is susceptible to Sensitive Information Exposure. Unauthenticated attackers can extract sensitive user data, including email addresses, hashed passwords, and IP addresses, by exploiting the predictable JSON file locations and guessable file names during user data export. This vulnerability could potentially lead to significant privacy breaches. Users are advised to upgrade to the latest version of the plugin or consider alternative solutions to manage user data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share