Impact
The vulnerability in the ERA404 StaffList WordPress plugin allows an attacker to retrieve sensitive embedded data, disclosing system information that should be restricted to authorized users. The primary impact is a confidentiality breach, enabling unauthorized users to access confidential data stored within the WordPress site.
Affected Systems
The affected product is the ERA404 StaffList WordPress plugin, specifically versions up to and including 3.2.7. Any WordPress installation that has this plugin at a vulnerable version is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity vulnerability. The EPSS score of less than 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is through a web-based interface that allows users to access or interact with the plugin. An attacker with access to the plugin administrative interface could trigger the data retrieval, exposing valuable information.
OpenCVE Enrichment
EUVD