Impact
The vulnerability is a classic sensitive data exposure flaw. Attackers can insert or observe sensitive information in the plugin's internal data handling, which is later written to logs. Those logs may be accessed by unauthorized users, enabling leakage of credentials, tokens or personal data. The flaw aligns with CWE‑201, indicating that confidentiality of data is at risk. No evidence of code execution or denial of service is mentioned.
Affected Systems
The issue affects the WordPress Crawlomatic Multisite Scraper Post Generator plugin from its earliest released version up to and including 2.6.8.2. Any WordPress site running this plugin, regardless of theme or other plugins, is exposed.
Risk and Exploitability
The CVSS base score of 5.3 marks it as medium severity. The EPSS < 1% suggests low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector appears to be through the plugin's data logging mechanisms, which may be triggered by normal operation or by an attacker who can manipulate the plugin's input fields. If the attacker cannot inject data through the plugin interface, the risk is reduced; however, sites where logs are publicly viewable pose a higher threat.
OpenCVE Enrichment
EUVD