Be POPIA Compliant <= 1.1.5 - Sensitive Information Exposure

2022-03-30 00:00
Chris Meistre

Strategic Overview

Status
Patched in 1.1.16
Affected PluginBe POPIA Compliant
Affected Version<= 1.1.5
CVSS5.3Medium
CVECVE-2022-1186
View all Be POPIA Compliant vulnerabilities

Vulnerability Overview

The WordPress plugin Be POPIA Compliant exposed sensitive information to unauthenticated users consisting of site visitors emails and usernames via an API route, in versions up to an including 1.1.5.

Technical Analysis

REMEDIATION: Update to version 1.1.16, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C