Impact
The WP System Information plugin for WordPress version 1.5 or earlier contains a vulnerability that allows unauthorized parties to retrieve embedded sensitive system information. This flaw leads to the disclosure of data that should be protected and can compromise confidentiality. The weakness is categorized as CWE‑497, which describes the risks of revealing sensitive data to unintended recipients.
Affected Systems
The affected product is the WP System Information plugin by Nurul Amin, deployed on WordPress installations. Any site running a version of the plugin through 1.5 is potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity level for confidentiality impact. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through publicly accessible plugin endpoints or information pages, making it possible for anyone with web access to the victim site to glean sensitive internal data.
OpenCVE Enrichment
EUVD