The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes.
https://wpscan.com/vulnerability/169e5756-4e12-4add-82e9-47471c30f08c/