GHSA-h47p-xxvg-g8pgHighCVSS 7.5
The Loops & Logic WordPress plugin before 4.3.0 does not restrict its public template-data action...
🔗 CVE IDs covered (1)
📋 Description
The Loops & Logic WordPress plugin before 4.3.0 does not restrict its public template-data action to the data a visitor is permitted to see, allowing unauthenticated users to read arbitrary user records (including email addresses and roles) and arbitrary site options.