Impact
The vulnerability is an improper limitation of a pathname to a restricted directory, commonly known as Path Traversal. It permits an attacker to craft a request that causes the Music Sheet Viewer plugin to read any file on the file system, thereby exposing sensitive configuration files, user data, or other confidential information. This weakness is categorized as CWE‑22 and can lead to data exfiltration and potential compromise of the site’s confidentiality.
Affected Systems
The defect is present in the Music Sheet Viewer plugin developed by efreja for WordPress, specifically affecting all releases from the initial version through 4.1 inclusive. Versions after 4.1 are not affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the flaw allows arbitrary file reads, an attacker does not need any special privileges or authentication to exploit it; the attack vector is inferred to be unauthenticated, relying on the plugin’s exposed file path handling. Given the potential to leak highly sensitive data, the risk remains significant for sites that have not patched the affected plugin version.
OpenCVE Enrichment
EUVD