Impact
The vulnerability is a missing authorization flaw in the Awesome Support plugin that allows an attacker to retrieve embedded sensitive data. The issue results in unauthorized access to private information that should be protected, potentially compromising user privacy and confidentiality. This weakness is classified as CWE-862.
Affected Systems
WordPress sites that use the awesomesupport:Awesome Support plugin version 6.3.6 or earlier are affected. The vulnerability exists in all releases from the earliest available build up through 6.3.6.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity risk. The EPSS score of less than 1% shows a low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely via HTTP requests to the plugin’s endpoints; an attacker must first have network access to the WordPress install and then exploit the missing authentication check to read protected data.
OpenCVE Enrichment
EUVD