CVE-2023-2623

The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:iqonic:kivicare:*:*:*:*:*:wordpress:*:*

History

07 Nov 2023, 04:12

Type Values Removed Values Added
CWE CWE-200

30 Jun 2023, 18:14

Type Values Removed Values Added
References (MISC) https://wpscan.com/vulnerability/85cc39b1-416f-4d23-84c1-fdcbffb0dda0 - (MISC) https://wpscan.com/vulnerability/85cc39b1-416f-4d23-84c1-fdcbffb0dda0 - Exploit, Third Party Advisory
First Time Iqonic kivicare
Iqonic
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:iqonic:kivicare:*:*:*:*:*:wordpress:*:*

27 Jun 2023, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-27 14:15

Updated : 2023-11-07 04:12


NVD link : CVE-2023-2623

Mitre link : CVE-2023-2623


JSON object : View

Products Affected

iqonic

  • kivicare
CWE

No CWE.