Vulnerability Bulletins

Authenticated Information Disclosure Vulnerability in Cherry Team Members

   
Affected software Wordpress
 
https://www.pluginvulnerabilities.com/2017/08/09/authenticated-information-disclosure-vulnerability-in-cherry-team-members/The plugin Cherry Team Members had the same authenticated information disclosure that the Cherry Services List had. The vulnerability was caused by the fact that contributor and author level users could duplicate posts that they would not have been able to edit. That could for example, have allowed them to gain access to the contents of password protected posts. The

More info:

https://www.pluginvulnerabilities.com/2017/08/09/authenticated-information-disclosure-vulnerability-in-cherry-team-members/