Be POPIA Compliant <= 1.1.5 - Sensitive Information Exposure
2022-03-30 00:00
Chris MeistreStrategic Overview
StatusPatched in 1.1.16
Affected PluginBe POPIA Compliant
Affected Version
<= 1.1.5CVSS5.3Medium
CVE
CVE-2022-1186Vulnerability Overview
The WordPress plugin Be POPIA Compliant exposed sensitive information to unauthenticated users consisting of site visitors emails and usernames via an API route, in versions up to an including 1.1.5.
Technical Analysis
REMEDIATION: Update to version 1.1.16, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C