The User Registration plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lock_content_form_handler' and 'display_password_form' function in versions up to, and including, 3.7.3. This makes it possible for unauthenticated attackers to decrypt and view the password protected content.
References
Configurations
History
No history.
Information
Published : 2023-06-27 02:15
Updated : 2023-11-07 04:18
NVD link : CVE-2023-3371
Mitre link : CVE-2023-3371
CVE.ORG link : CVE-2023-3371
JSON object : View
Products Affected
wpdeveloper
- embedpress
CWE
No CWE.