← Back to CVE List

CVE-2023-2623

Published: 2023-06-27T14:15Z
Last Modified: 2024-11-21T07:58Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users > MITRE Terms of Use apply – see LICENSE‑MITRE.txt