CVE-2023-2623

The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:iqonic:kivicare:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2023-06-27 14:15

Updated : 2023-11-07 04:12


NVD link : CVE-2023-2623

Mitre link : CVE-2023-2623

CVE.ORG link : CVE-2023-2623


JSON object : View

Products Affected

iqonic

  • kivicare
CWE

No CWE.