Impact
Insertion of Sensitive Information Into Sent Data vulnerability in the Themeum Qubely plugin allows attackers to retrieve embedded sensitive data. The flaw resides in how the plugin handles and transmits data, causing confidential information to be exposed. This is a classic Sensitive Data Exposure (CWE‑201) issue, potentially compromising confidentiality without affecting integrity or availability.
Affected Systems
The vulnerability affects Themeum Qubely, a WordPress plugin, across all versions up to and including 1.8.14. Users operating the plugin on any WordPress installation within this version range are susceptible to the data exposure flaw.
Risk and Exploitability
The CVSS base score is 4.3, indicating a moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is normal operation of the plugin, where attackers may gather sensitive data from plugin output or API responses (inferred from the description).
OpenCVE Enrichment
EUVD