Description
wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Accessibility Cross-Site Scripting (1.6.10)
WordPress Plugin WordPress Download Manager Cross-Site Request Forgery (3.2.12)
Restlet Framework XML Injection (aka Blind XPath Injection) Vulnerability (CVE-2013-4221)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-31546)