vulnerability

WordPress Plugin: pmpro-member-directory: CVE-2024-1287: Authorization Bypass Through User-Controlled Key

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
Jul 9, 2024
Added
May 15, 2025
Modified
Jul 10, 2025

Description

The Paid Memberships Pro - Member Directory Add On plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 1.2.6 (exclusive) through the 'pmpro_member_directory' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to extract sensitive user meta data, including password hashes.

Solution

pmpro-member-directory-plugin-cve-2024-1287
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.