Impact
The vulnerability originates in the StellarWP Give – Divi Donation Modules plugin version 2.0.0 or earlier, where the plugin inadvertently stores sensitive information in files or directories that are publicly accessible. This design flaw permits an attacker to retrieve the embedded sensitive data, exposing confidential information. The issue is categorized as CWE‑538, which defines the risk of Sensitive Data Exposure through information stored in publicly‑readable files.
Affected Systems
All releases of the Give – Divi Donation Modules plugin from the initial release up through version 2.0.0 are affected. Site administrators using any of these versions should verify their installed plugin version and plan for an upgrade. The vulnerability has been observed by multiple security researchers and is documented in the plugin's changelog and external advisories.
Risk and Exploitability
With a CVSS score of 5.8, the flaw is classified as moderate. The EPSS score is below 1 %, indicating a low probability of exploitation at the time of this assessment, and the vulnerability is not listed in the CISA KEV catalog. Likely, an attacker would discover the exposed files through a standard web scan or by browsing the plugin directory, then read the files to obtain sensitive data. Until the plugin is updated, restricting access to the plugin’s directories through server permissions or web‑server configuration can reduce the attack surface.
OpenCVE Enrichment
EUVD