CVE-2024-8106

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.8 via the download_user_ajax function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including usernames, hashed passwords, and emails.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpextended:wp_extended:*:*:*:*:*:wordpress:*:*

History

05 Sep 2024, 13:05

Type Values Removed Values Added
First Time Wpextended
Wpextended wp Extended
CPE cpe:2.3:a:wpextended:wp_extended:*:*:*:*:*:wordpress:*:*
CWE NVD-CWE-noinfo
References () https://plugins.trac.wordpress.org/browser/wpextended/trunk/includes/modules/core_extensions/wpext_export_users/wpext_export_users.php#L54 - () https://plugins.trac.wordpress.org/browser/wpextended/trunk/includes/modules/core_extensions/wpext_export_users/wpext_export_users.php#L54 - Product
References () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3145430%40wpextended%2Ftrunk&old=3134345%40wpextended%2Ftrunk&sfp_email=&sfph_mail= - () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3145430%40wpextended%2Ftrunk&old=3134345%40wpextended%2Ftrunk&sfp_email=&sfph_mail= - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/593eb5bc-59f9-4944-b147-4ba66d49abe6?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/593eb5bc-59f9-4944-b147-4ba66d49abe6?source=cve - Third Party Advisory

04 Sep 2024, 13:05

Type Values Removed Values Added
Summary
  • (es) El complemento The Ultimate WordPress Toolkit – WP Extended para WordPress es vulnerable a la exposición de información confidencial en todas las versiones hasta la 3.0.8 incluida a través de la función download_user_ajax. Esto permite que atacantes autenticados, con acceso de nivel de suscriptor o superior, extraigan datos confidenciales, incluidos nombres de usuario, contraseñas cifradas y correos electrónicos.

04 Sep 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-04 07:15

Updated : 2024-09-05 13:05


NVD link : CVE-2024-8106

Mitre link : CVE-2024-8106

CVE.ORG link : CVE-2024-8106


JSON object : View

Products Affected

wpextended

  • wp_extended
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor