What the vulnerability does
01Description
The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the 'wpbb' shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including arbitrary user_meta values.
Explanation of Vulnerability in Simple Terms
02Summary
Beaver Themer versions up to 1.4.9 expose sensitive user data to authenticated attackers. An attacker with a low-privilege account can read information they should not have access to. The vulnerability requires login but no additional user interaction. Update to a version newer than 1.4.9 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read sensitive information belonging to other users or the site.
Potential impact on your site
04Site Impact
User data privacy is at risk if any low-privilege accounts are compromised or created by attackers.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account on the site; no user interaction required.
Key dates
06Disclosure timeline
April 9, 2024
CVE published
April 8, 2026
Record updated