VulnerabilityModified
CVE-2021-25110
The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user's email address.
MEDIUM 4.3EPSS 0.90%
Does this matter?
Lower severity and a low EPSS score (0.90%). Track it; it rarely justifies an emergency change on its own.
Description
The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user's email address.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.90% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- futuriowp/futurio extra
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/b655fc21-47a1-4786-8911-d78ab823c153Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/b655fc21-47a1-4786-8911-d78ab823c153Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.