Impact
The Analytify Pro WordPress plugin contains a sensitive information exposure flaw that allows unauthenticated users to view usernames embedded in the source code via the Analytify Tag HTML details function. This vulnerability enables attackers to access usernames without requiring any credentials, but it does not provide a route to alter or disrupt the underlying system.
Affected Systems
All installations of Analytify Pro version 7.0.3 or earlier running on a WordPress site may be affected, independent of theme or other plugins, because the flaw resides within the plugin code itself.
Risk and Exploitability
The CVSS score of 5.3 classifies this as moderate, while an EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it without authentication by simply visiting a site that contains the vulnerable plugin and viewing the publicly accessible pages containing the Tag HTML details.
OpenCVE Enrichment