CVE Published: 06/09/2022 |
CVE Updated: 17/09/2024 |
CVE Year: 2022 Source: Patchstack |
Vendor: Libreform |
Product: WP Libre Form 2 (WordPress plugin) Status : PUBLISHED
CVE-2022-34867 Description
Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin <= 2.0.8 at WordPress allows attackers to list and delete submissions. Affects only versions from 2.0.0 to 2.0.8.
Metrics
CVSS Version: 3.1 |
Base Score: 7.3 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L