Impact
The wpLike2Get plugin allows an attacker to retrieve sensitive data embedded within the plugin by exposing system information normally protected from an unauthorized control sphere. This flaw is categorized as CWE-497, an information disclosure weakness that occurs when protected data is inadvertently disclosed through improper handling.
Affected Systems
All installations of Markus Drubba’s wpLike2Get plugin up to and including version 1.2.9 are affected. No specific sub‑versions are listed, so every release prior to 1.3.0 inherits the vulnerability.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack path involves interacting with the plugin’s functionality—such as visiting an administrative page or triggering a plugin endpoint—which permits the disclosure of sensitive data; the description does not specify an explicit prerequisite beyond plugin activation, so the attack vector is assumed to be local or web‑based.
OpenCVE Enrichment
EUVD