CVE-2020-13764
HIGHRocketgenius Gravityforms < 2.4.9 - Information Disclosure
Title source: ruleDescription
common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://docs.gravityforms.com/gravityforms-change-log/
Third Party Advisory x_refsource_misc
https://github.com/wp-premium/gravityforms/compare/2.4.8...2.4.9
Scores
CVSS v3
7.5
EPSS
0.0183
EPSS Percentile
76.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (2)
rocketgenius/gravityforms
< 2.4.9
wp-premium/gravityforms
0 - 2.4.9Packagist
Published
Jun 02, 2020
Tracked Since
Feb 18, 2026