Access violation vulnerability in User Meta – User Profile Builder and User management plugin 3.1

A popular plugin for WordPress called “User Meta – User Profile Builder and User Management” has a security vulnerability in all versions up to 3.1. This vulnerability allows attackers with Contributor-level access or higher to view sensitive information, such as password hashes, from form fields. It is important for site administrators to be cautious when creating forms that display this type of information. Additionally, even unauthenticated users can exploit this vulnerability if the ‘user-meta-public-profile’ shortcode is not used securely.

Detected in:

User Meta – User Profile Builder and User management plugin open vulnerable versions: >= * <= 3.1.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.