CVE-2023-6733

MEDIUM

WP-Members Membership Plugin <= 3.4.8 - Authenticated Sensitive Information Exposure via wpmem_field Shortcode

Title source: llm
STIX 2.1

Description

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including user emails, password hashes, usernames, and more.

Scores

CVSS v3 6.5
EPSS 0.0044
EPSS Percentile 35.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-862
Status published
Products (2)
butlerblog/wp-members < 3.4.8
cbutlerjr/WP-Members Membership Plugin < 3.4.8
Published Jan 04, 2024
Tracked Since Feb 18, 2026