CVE-2024-12637
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Jan 17, 2025
CWE ID 200
Summary
CVE-2024-12637: The WordPress plugin "Moving Users" with versions up to 1.05 is susceptible to Sensitive Information Exposure. Unauthenticated attackers can extract sensitive user data, including email addresses, hashed passwords, and IP addresses, by exploiting the predictable JSON file locations and guessable file names during user data export. This vulnerability could potentially lead to significant privacy breaches. Users are advised to upgrade to the latest version of the plugin or consider alternative solutions to manage user data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.