CVE-2024-1279medium

CVE-2024-1279: medium-severity vulnerability in Paid Memberships Pro

Paid Memberships Pro < 2.12.9 - Contributor+ Arbitrary User Custom Field Disclosure

Published · Updated

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.3epss 0.5%
exploitation probability
0.5%top 56% of all CVEs
observed exploitation
nono source reports it
The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N