Impact
An issue was identified in the ProofreadPage extension for MediaWiki versions through 1.39.3 that permits the revelation of data about suppressed users via the extension’s API and certain configuration variables. The flaw is a classic information‑disclosure weakness (CWE‑669). If an attacker can query the API or read the relevant configuration data, they may discover the identities or status of users that administrators intended to hide, potentially exposing sensitive user relationships or activity logs.
Affected Systems
The vulnerability impacts the MediaWiki ProofreadPage extension up to and including version 1.39.3. Any installation of this extension released at that point or earlier is susceptible. No other MediaWiki components are listed as affected.
Risk and Exploitability
The CVSS base score of 3.1 signals a low severity. An EPSS score of less than 1% reflects a very low likelihood of exploitation, and the issue is absent from the CISA KEV catalog. The presumed attack vectors are through the public API, which a remote attacker could use, or by accessing configuration files, which would require local read permissions. Given the low score, the immediate threat is modest, but exposed suppressed user data can still aid targeted social engineering or compliance investigations.
OpenCVE Enrichment