Impact
An insertion of sensitive information into externally‑accessible files or directories allows attackers to retrieve embedded data such as passwords, keys or configuration information. The vulnerability is classified as CWE‑538 and carries a moderate CVSS score of 5.8, indicating potential confidentiality exposure if exploited. The flaw can be leveraged to read data that was not intended to be publicly available.
Affected Systems
The WP‑LESS plugin for WordPress, distributed by thom4, is affected in all versions from the earliest release up to 1.9.6. Any WordPress installation using this plugin version may be vulnerable to the sensitive data exposure issue.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, implying a low probability of active exploitation at present. Still, the CVSS score of 5.8 denotes a moderate impact if an attacker can access the exposed files, potentially resulting in credential theft or other privacy violations. The attack vector is likely remote or local depending on the web server configuration, with exposure occurring when the plugin’s files are publicly reachable. It is advisable to consider the risk moderate while remediation is planned.
OpenCVE Enrichment
EUVD