Impact
The vulnerability is an insertion of sensitive information into sent data in the Viral Loops WP Integration plugin, allowing attackers to retrieve embedded sensitive data. This flaw permits an adversary to read confidential information that should not be transmitted. CWE-201 identifies it as a reliable data disclosure weakness.
Affected Systems
viralloops Viral Loops WP Integration plugin for WordPress, all versions up to and including 3.4.0.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation at present. The plugin is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is remote, requiring network access to the affected WordPress site; an attacker can exploit the plugin’s data handling routine to capture sensitive information transmitted to a client.
OpenCVE Enrichment
EUVD