CVE-2023-5134
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2023-5134 is a vulnerability affecting the Easy Registration Forms plugin for WordPress. This issue allows authenticated attackers with subscriber-level access or higher to disclose sensitive user information through the 'erforms_user_meta' shortcode, which is present in versions up to and including 2.1.1. The vulnerability stems from insufficient controls over the data retrieved by the shortcode, enabling attackers to access arbitrary sensitive user meta, posing a significant risk to user privacy. Users are strongly advised to update to the latest plugin version to address this information disclosure issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.