Impact
The vulnerability allows the SureDash plugin to insert and expose sensitive data in outgoing communications, enabling an attacker to retrieve protected information from WordPress sites. This is a classic Sensitive Data Exposure flaw identified as CWE-201, which can compromise confidentiality of user data and site configurations.
Affected Systems
Brainstorm Force SureDash plugin versions up to and including 1.1.0 are affected. The issue exists across all releases from the earliest known version through 1.1.0.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that an attacker could potentially exploit the flaw by accessing the plugin’s interface or API, which may allow them to trigger the data retrieval path. Because the information is exposed in transmitted data, the threat primarily concerns confidentiality compromise rather than denial of service or privilege escalation.
OpenCVE Enrichment
EUVD