PT-2024-17770 · Unknown · Pmpro-Member-Directory

Scott Kingsley Clark

·

Published

2024-07-30

·

Updated

2025-08-22

·

CVE-2024-1287

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions pmpro-member-directory versions prior to 1.2.6
Description The issue allows users with at least the contributor role to leak other users' sensitive information, including password hashes.
Recommendations For versions prior to 1.2.6, update to version 1.2.6 or later to resolve the issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-1287

Affected Products

Pmpro-Member-Directory