The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authenticated users such as subscriber to retrieve arbitrary user meta (except the user_pass), such as the user email and activation key by default.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-25T20:28:41.019Z
Reserved: 2023-02-18T09:44:16.619Z
Link: CVE-2023-0911

Updated: 2024-08-02T05:24:34.722Z

Status : Modified
Published: 2023-03-20T16:15:12.800
Modified: 2025-02-25T21:15:10.700
Link: CVE-2023-0911

No data.