Impact
The SiteAlert (Formerly WP Health) plugin for WordPress has a missing capability check on several AJAX functions in all versions up to and including 1.9.8. This weakness allows anyone on the internet who can send unauthenticated HTTP requests to these endpoints to view detailed site health information, such as the list of installed plugins, which plugins are outdated, the PHP version, and the database version. The disclosure of this information can be leveraged in subsequent targeted attacks, as it provides a ready inventory of potential attack vectors and system configuration details.
Affected Systems
This vulnerability affects the SiteAlert (Formerly WP Health) WordPress plugin for all releases up to and including version 1.9.8. Users running any of these versions on a WordPress installation are potentially exposed unless the plugin is upgraded or protected by external means.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate overall impact, and the EPSS score of less than 1% reflects a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker can reach the vulnerable AJAX endpoints via unauthenticated HTTP requests, thereby reading the site health data without needing any credentials.
OpenCVE Enrichment
EUVD