WordPress Plugin Vulnerabilities

User Profile Picture < 2.5.0 - Sensitive Information Disclosure

Description

The REST API endpoint get_users in the plugin returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

Proof of Concept

Affects Plugins

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Chloe Chamberland
Submitter
Chloe Chamberland
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2021-03-03 (about 4 years ago)
Added
2021-03-03 (about 4 years ago)
Last Updated
2021-04-03 (about 4 years ago)

Other