Record summary

CVE-2024-6477 has a selected CVSS score of 7.5 (high).

Description

The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive information such as IP, username, and email address

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

UsersWP

Default status: unaffected

CVE ListBefore 1.2.12affected

Default status: unaffected

CVE ListBefore 1.2.12affected

References

2