CVE Database
/

CVE-2024-6477

Back to search

CVE-2024-6477

Published: Aug 3, 2024

Modified: Aug 27, 2025

PUBLISHED

Description

The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive information such as IP, username, and email address

VendorProductVersions

Unknown

UsersWP

affected
0 - < 1.2.12

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now