CVE-2021-24170 Scanner
CVE-2021-24170 Scanner - Information Disclosure vulnerability in User Profile Picture
Used 3.2k times · 5.9k assets checked · domain, subdomain, ipv4
The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. This included password hashes, hashed user activation keys, usernames, emails, and other less sensitive information.
CVE-2021-24170 Scanner - Information Disclosure vulnerability in User Profile Picture
Used 3.2k times · 5.9k assets checked · domain, subdomain, ipv4
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →