2 results (0.003 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files. El complemento FastDup de WordPress anterior a 2.2 no impide el listado de directorios en directorios confidenciales que contienen archivos de exportación. The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.9. This makes it possible for unauthenticated attackers to obtain exports that include sensitive information such as user password hashes. • https://research.cleantalk.org/cve-2023-6592-fastdup-database-users-password-leak-poc-exploit https://wpscan.com/vulnerability/a39bb807-b143-4863-88ff-1783e407d7d4 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FastDup – Fastest WordPress Migration & Duplicator.This issue affects FastDup – Fastest WordPress Migration & Duplicator: from n/a through 2.1.7. Exposición de información confidencial a una vulnerabilidad de actor no autorizado en Ninja Team FastDup: duplicador y migración de WordPress más rápido. Este problema afecta a FastDup: duplicador y migración de WordPress más rápido: desde n/a hasta 2.1.7. The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.7 via the plugin's log file. This makes it possible for unauthenticated attackers to extract sensitive data including system and plugin configurartion • https://patchstack.com/database/vulnerability/fastdup/wordpress-fastdup-plugin-2-1-7-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-532: Insertion of Sensitive Information into Log File •