CVE-2020-13764

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
02/06/2020
Last modified:
03/06/2020

Description

common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rocketgenius:gravityforms:*:*:*:*:*:wordpress:*:* 2.4.9 (excluding)