Impact
The WP Mailster plugin contains a vulnerability that allows an attacker to insert sensitive information into outgoing data, leading to exposure of confidential content that may include credentials or personal details. This flaw is classified as CWE‑201 and carries a CVSS score of 6.5, indicating a moderate severity level for confidentiality impact.
Affected Systems
The affected product is the WordPress WP Mailster plugin from brandtoss, version 1.8.16.0 and all earlier releases. Sites that have a WordPress installation with this plugin are vulnerable, regardless of other configuration settings.
Risk and Exploitability
The EPSS score of less than 1 % suggests that exploitation of this weakness is currently considered low probability, and it is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker could exploit the plugin by crafting requests to the mail sending functions or by accessing the plugin’s administration area to retrieve embedded sensitive data. The exact attack vector is not specified in the advisory, so defensive measures should treat both remote and local exploitation scenarios as possible.
OpenCVE Enrichment
EUVD