Description
Insertion of Sensitive Information into Log File vulnerability in DualCube MooWoodle moowoodle allows Retrieve Embedded Sensitive Data.This issue affects MooWoodle: from n/a through <= 3.2.4.
Published: 2025-02-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from the way DualCube MooWoodle writes data to its log files, causing confidential information that users submit through the plugin to be stored in logs without proper filtering. Based on the description, it is inferred that an attacker who can supply crafted input to the plugin’s form endpoints can embed sensitive data, which will then be indiscriminately recorded. This enables an unauthenticated or minimally privileged attacker to read the logs and recover private data, resulting in a breach of confidentiality.

Affected Systems

The issue affects the WordPress MooWoodle plugin from its initial release up through and including version 3.2.4. Any installation of MooWoodle that has not been updated beyond the last officially released version is potentially vulnerable, regardless of site configuration or other plugins present.

Risk and Exploitability

With a CVSS score of 7.5 the flaw is considered high severity, and the EPSS score of less than 1% indicates a low exploitation probability, though it is still exploitable in the remote, unauthenticated context. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector, inferred from the description, is remote web requests to the MooWoodle form handlers; an attacker can subvert the logging mechanism by submitting maliciously crafted requests that cause sensitive data to be written to server logs, which can then be accessed by privileged users or compromised accounts.

Generated by OpenCVE AI on May 2, 2026 at 09:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact DualCube to obtain a vendor‑specific fix or guidance on mitigating the logging issue
  • If a fix is not immediately available, reconfigure the server logging to exclude or sanitize sensitive fields and disable automatic request logging for the MooWoodle form endpoints
  • Regularly audit log files for unintended sensitive entries and remove them promptly to restrict data exposure

Generated by OpenCVE AI on May 2, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3764 Insertion of Sensitive Information into Log File vulnerability in DualCube MooWoodle allows Retrieve Embedded Sensitive Data. This issue affects MooWoodle: from n/a through 3.2.4.
History

Wed, 29 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information into Log File vulnerability in DualCube MooWoodle allows Retrieve Embedded Sensitive Data. This issue affects MooWoodle: from n/a through 3.2.4. Insertion of Sensitive Information into Log File vulnerability in DualCube MooWoodle moowoodle allows Retrieve Embedded Sensitive Data.This issue affects MooWoodle: from n/a through <= 3.2.4.
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00054}

epss

{'score': 0.00068}


Mon, 03 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Feb 2025 14:30:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information into Log File vulnerability in DualCube MooWoodle allows Retrieve Embedded Sensitive Data. This issue affects MooWoodle: from n/a through 3.2.4.
Title WordPress MooWoodle plugin <= 3.2.4 - Sensitive Data Exposure vulnerability
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:51:54.282Z

Reserved: 2025-01-23T14:50:25.793Z

Link: CVE-2025-24556

cve-icon Vulnrichment

Updated: 2025-02-03T16:23:50.379Z

cve-icon NVD

Status : Deferred

Published: 2025-02-03T15:15:24.360

Modified: 2026-04-29T10:16:41.290

Link: CVE-2025-24556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T09:30:20Z

Weaknesses