Impact
The vulnerability resides in the Paytium plugin for WordPress, where an error message reveals the absolute filesystem location of files. This disclosure can expose confidential system paths and compromise the confidentiality of the environment. The weakness corresponds to input validation failures documented as CWE-209.
Affected Systems
Affected customers run Paytium on WordPress with version 4.4.11 or earlier. The plugin is maintained by paytiumsupport and the issue covers all releases from the earliest available version up through 4.4.11.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. It is likely that a remote attacker who can trigger the error (for example by manipulating plugin input) could obtain the full path information. No further exploitation steps, such as privilege escalation, are indicated in the available data.
OpenCVE Enrichment
EUVD