The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user's email address.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/b655fc21-47a1-4786-8911-d78ab823c153 | third party advisory exploit |