Vulnerability Description
common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rocketgenius | Gravityforms | < 2.4.9 |
Related Weaknesses (CWE)
References
- https://docs.gravityforms.com/gravityforms-change-log/Vendor Advisory
- https://github.com/wp-premium/gravityforms/compare/2.4.8...2.4.9Third Party Advisory
- https://docs.gravityforms.com/gravityforms-change-log/Vendor Advisory
- https://github.com/wp-premium/gravityforms/compare/2.4.8...2.4.9Third Party Advisory
FAQ
What is CVE-2020-13764?
CVE-2020-13764 is a vulnerability with a CVSS score of 7.5 (HIGH). common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.
How severe is CVE-2020-13764?
CVE-2020-13764 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13764?
Check the references section above for vendor advisories and patch information. Affected products include: Rocketgenius Gravityforms.