CVE-2024-9262

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Nov 9, 2024
Updated: Nov 12, 2024
CWE ID 639

Summary

CVE-2024-9262 is a vulnerability affecting the User Meta – User Profile Builder and User management plugin for WordPress. This issue, present in all versions up to 3.1, allows authenticated attackers with Contributor-level access or higher to gain unauthorized access to user meta values through an Insecure Direct Object Reference in the getUser() function. This vulnerability arises due to missing validation on a user-controlled key. If a site administrator creates a form displaying sensitive information like password hashes, an attacker can exploit this. Furthermore, unauthenticated users may also exploit the 'user-meta-public-profile' shortcode if used insecurely.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share