Showing 1 vulnerability on this page for user_profile_picture

Signals CISA KEV Ransomware Nuclei
cozmoslabs vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

User Profile Picture < 2.5.0 - Sensitive Information Disclosure

The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.

CWE-200Apr 5, 20211 related artifact
CVSS7.5v3.1EPSS4.79%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX