CVE-2024-6477 Information

Description

The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export which could allow unauthenticated attackers to download them and retrieve sensitive information such as IP username and email address

Reference

https://wpscan.com/vulnerability/346c855a-4d42-4a87-aac9-e5bfc2242b16/

Share on: