What the vulnerability does
01Description
Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.
Explanation of Vulnerability in Simple Terms
Polylang versions up to 3.8.5 expose sensitive information to authenticated users with low privileges. An attacker with a standard user account can read data they should not have access to. The vulnerability requires network access and an active login but does not require user interaction beyond authentication.
What an attacker can do
Read sensitive data accessible only to higher-privilege users.
Potential impact on your site
User account data and settings may be exposed to standard users who should not see them.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities