Impact
The vulnerability in Metagauss ProfileGrid plugin allows an unauthorized user to retrieve sensitive system information, specifically file path details, through a Full Path Disclosure flaw identified as CWE-497. This flaw does not provide direct code execution or privilege escalation but can reveal directory structure and internal configuration, potentially facilitating future attacks by an adversary with knowledge of the environment.
Affected Systems
Metagauss ProfileGrid plugin versions up to and including 5.9.5.2 are affected. Any WordPress installation using this plugin within that version range is vulnerable.
Risk and Exploitability
Based on the description, it is inferred that attackers could exploit the flaw remotely by accessing plugin URLs that expose internal paths or debugging endpoints. The CVSS score of 4.3 indicates moderate severity, while an EPSS rating of less than 1% implies a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The risk lies primarily in the disclosure of sensitive system configuration that could aid in subsequent attacks, but the flaw does not grant code execution, file modification or privilege escalation.
OpenCVE Enrichment
EUVD