Impact
Direct Payments WP fails to safeguard sensitive data embedded in its responses, permitting unauthorized actors to retrieve that data. The vulnerability is identified as CWE‑497, allowing a moderate breach of confidentiality for the WordPress site and its users.
Affected Systems
This flaw affects the Digages Direct Payments WP plugin for WordPress versions up to and including 1.3.2. Administrators who have installed any of these versions are potentially exposed.
Risk and Exploitability
The CVSS score of 4.3 reflects a moderate risk level, and the EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker could obtain the exposed sensitive data by accessing the plugin’s publicly exposed pages or API endpoints, which are typically reachable from the web. This suggests the attack surface is moderate, but the lack of additional exploitation details limits a precise assessment of attack feasibility.
OpenCVE Enrichment