Gravityforms <= 2.4.8 - Information Exposure

2019-05-08 00:00
Anonymous

Strategic Overview

Status
Patched in 2.4.9
Affected PluginGravity Forms
Affected Version<= 2.4.8
CVSS7.5High
CVECVE-2020-13764
View all Gravity Forms vulnerabilities

Vulnerability Overview

common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.

Technical Analysis

REMEDIATION: Update to version 2.4.9, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C