Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beee ACF City Selector acf-city-selector allows Retrieve Embedded Sensitive Data.This issue affects ACF City Selector: from n/a through <= 1.17.0.
Published: 2025-04-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Beee ACF City Selector plugin permits an unauthorized user to retrieve embedded sensitive system information from the plugin’s configuration or internal data. This is a classic data‑exposure flaw that can leak configuration details and potentially other hidden values that the plugin stores. The weakness is classified as CWE-497, indicating improper handling of sensitive data and failing to restrict access appropriately.

Affected Systems

The affected vendor is Beee with the ACF City Selector plugin. All released versions up to and including 1.17.0 are impacted, as the vulnerability description indicates a range from the first release through 1.17.0. Users who have not upgraded beyond that version should verify whether a newer release is available or if the plugin is still installed.

Risk and Exploitability

The CVSS score of 5.3 places this issue in the medium severity band. While the EPSS score is less than 1%, indicating low probability of exploitation in the wild, the lack of a KEV listing does not remove the risk of data leakage to attackers who can discover the plugin. The likely attack vector is via the web interface where the plugin is active, possibly requiring only authenticated user privileges or no authentication if the plugin exposes data to all users. An attacker gains read‑only access to sensitive configuration data, compromising confidentiality.

Generated by OpenCVE AI on May 1, 2026 at 01:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the ACF City Selector plugin to the latest available version that resolves the data‑exposure flaw.
  • If an upgrade is not immediately possible, fully disable or remove the plugin from the WordPress installation to prevent further exposure.
  • Configure WordPress user roles to ensure that only trusted administrators can access pages that load the ACF City Selector plugin, thereby limiting the potential attack surface.

Generated by OpenCVE AI on May 1, 2026 at 01:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9207 Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beee ACF City Selector allows Retrieve Embedded Sensitive Data. This issue affects ACF City Selector: from n/a through 1.16.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beee ACF City Selector allows Retrieve Embedded Sensitive Data. This issue affects ACF City Selector: from n/a through 1.16.0. Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beee ACF City Selector acf-city-selector allows Retrieve Embedded Sensitive Data.This issue affects ACF City Selector: from n/a through <= 1.17.0.
Title WordPress ACF City Selector plugin <= 1.16.0 - Sensitive Data Exposure vulnerability WordPress ACF City Selector plugin <= 1.17.0 - Sensitive Data Exposure vulnerability
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 01 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beee ACF City Selector allows Retrieve Embedded Sensitive Data. This issue affects ACF City Selector: from n/a through 1.16.0.
Title WordPress ACF City Selector plugin <= 1.16.0 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:13.927Z

Reserved: 2025-04-01T13:20:41.853Z

Link: CVE-2025-31832

cve-icon Vulnrichment

Updated: 2025-04-01T19:12:03.995Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:23.493

Modified: 2026-04-23T15:28:22.810

Link: CVE-2025-31832

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T02:00:06Z

Weaknesses