vendor:
WP Guppy
by:
Keyvan Hardani
8.8
CVSS
HIGH
Sensitive Information Disclosure
200
CWE
Product Name: WP Guppy
Affected Version From: 1.1
Affected Version To: 1.1
Patch Exists: YES
Related CWE:
CPE: a:wp-guppy:wp_guppy
Platforms Tested: Kali Linux, Windows 10, Wordpress 5.8.x, Apache2
2021
WordPress Plugin WP Guppy 1.1 – WP-JSON API Sensitive Information Disclosure
This exploit allows an attacker to gain access to sensitive information from the WP Guppy plugin by using the WP_JSON API. The attacker can use the exploit to get all users, send messages from/to other users, and get the chats between users.
Mitigation:
The user should update the WP Guppy plugin to the latest version.