Impact
Insertion of sensitive information into data sent by the WM Options Import Export plugin allows unauthorized parties to retrieve embedded confidential data. The flaw facilitates unintended disclosure of sensitive data that can be exploited to undermine the security of a WordPress site. The weakness corresponds to CWE‑201, Sensitive Information Exposure.
Affected Systems
The vulnerability affects all releases of the Web Mumbai WM Options Import Export plugin for WordPress up to and including version 1.0.1. Any site using an outdated instance of this plugin is at risk.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high risk to confidentiality, while the EPSS score of less than 1% suggests exploitation is currently rare and it is not listed in the CISA KEV catalog. The likely attack vector involves an attacker with privileged access to the WordPress administration interface leveraging the import/export functionality, or a situation where a crafted export file containing embedded sensitive information is introduced through the plugin's data structures.
OpenCVE Enrichment
EUVD