CVE-2024-9262
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-9262 is a vulnerability affecting the User Meta – User Profile Builder and User management plugin for WordPress. This issue, present in all versions up to 3.1, allows authenticated attackers with Contributor-level access or higher to gain unauthorized access to user meta values through an Insecure Direct Object Reference in the getUser() function. This vulnerability arises due to missing validation on a user-controlled key. If a site administrator creates a form displaying sensitive information like password hashes, an attacker can exploit this. Furthermore, unauthenticated users may also exploit the 'user-meta-public-profile' shortcode if used insecurely.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.