What the vulnerability does
01Description
Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions.
Explanation of Vulnerability in Simple Terms
WPJAM Basic through version 7.0.2.1 contains an information disclosure vulnerability that allows unauthenticated attackers to read sensitive data over the network without user interaction. The vulnerability stems from improper access controls on a sensitive function. No integrity or availability impact is present. Update to a version newer than 7.0.2.1.
What an attacker can do
Read sensitive information from the site without logging in.
Potential impact on your site
Confidential data may be exposed to anyone on the internet who knows how to request it.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities