Impact
The Chamber Dashboard Business Directory plugin for WordPress contains a missing capability check in the cdash_watch_for_export() function, allowing anyone who can access the plugin’s export endpoint to retrieve business directory information without authentication. The data may include sensitive business details, so an attacker could gain confidential information by simply triggering an export.
Affected Systems
The vulnerability affects all installations of the Chamber Dashboard Business Directory plugin with versions up to and including 3.3.11 on any WordPress site that has the plugin enabled. No other vendors or products are noted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests that exploitation is unlikely to be widespread at present. The plug‑in exposes an HTTP endpoint that does not perform a capability check, making the exploit possible even from unauthenticated traffic. Because the flaw is present in all prior releases, sites running any affected version are at risk of data disclosure; the issue is not listed in CISA’s KEV catalog.
OpenCVE Enrichment