vendor:
User Meta Manager
by:
Panagiotis Vagenas
7,5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: User Meta Manager
Affected Version From: 3.4.6
Affected Version To: 3.4.7
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress 4.4
2015
WordPress User Meta Manager Plugin [Information Disclosure]
User Meta Manager for WordPress plugin up to v3.4.6 suffers from a information disclosure vulnerability. Any registered user can perform an a series of AJAX requests, in order to get all contents of `usermeta` DB table. `usermeta` table holds additional information for all registered users. User Meta Manager plugin offers a `usermeta` table backup functionality. During the backup process the plugin takes no action in protecting the leakage of the table contents to unauthorized (non-admin) users.
Mitigation:
Upgrade to version 3.4.8 or later.