{"id":"GHSA-29qv-hhg4-6x96","summary":"Unauthenticated Sensitive Information Disclosure vulnerability","details":"Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin \u003c= 2.0.8 at WordPress allows attackers to list and delete submissions. Affects only versions from 2.0.0 to 2.0.8.","aliases":["CVE-2022-34867"],"modified":"2024-04-24T21:01:45.244467Z","published":"2022-09-07T00:01:53Z","database_specific":{"cwe_ids":["CWE-200","CWE-668"],"github_reviewed_at":"2024-04-24T20:41:54Z","github_reviewed":true,"nvd_published_at":"2022-09-06T18:15:00Z","severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-34867"},{"type":"WEB","url":"https://github.com/libreform/libreform/pull/54/files"},{"type":"PACKAGE","url":"https://github.com/libreform/libreform"},{"type":"WEB","url":"https://patchstack.com/database/vulnerability/libreform/wordpress-wp-libre-form-2-plugin-2-0-8-unauthenticated-sensitive-information-disclosure-vulnerability"}],"affected":[{"package":{"name":"libreform/libreform","ecosystem":"Packagist","purl":"pkg:composer/libreform/libreform"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.9"}]}],"versions":["2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.6.1","2.0.7","2.0.8"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.0.8","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-29qv-hhg4-6x96/GHSA-29qv-hhg4-6x96.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}