What the vulnerability does
01Description
Insecure Storage of Sensitive Information vulnerability in WPMU DEV Defender Security allows : Screen Temporary Files for Sensitive Information.This issue affects Defender Security: from n/a through 3.3.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
What the vulnerability does
Insecure Storage of Sensitive Information vulnerability in WPMU DEV Defender Security allows : Screen Temporary Files for Sensitive Information.This issue affects Defender Security: from n/a through 3.3.2.
Explanation of Vulnerability in Simple Terms
Defender Security through version 3.3.2 contains a flaw that allows authenticated users with low privileges to read, modify, or disrupt site data. The vulnerability requires network access and high attack complexity, limiting its practical exploitability. Site administrators should update to a version newer than 3.3.2 to mitigate this risk.
What an attacker can do
Read, modify, or disrupt site data with a low-privilege authenticated account.
Potential impact on your site
Authenticated users can access or alter sensitive data; availability of site functions may be affected.
Conditions required to exploit
Attacker must have a low-privilege user account on the site; high attack complexity required.
Key dates
External resources
Related vulnerabilities