Description
Insertion of Sensitive Information Into Sent Data vulnerability in jetmonsters Getwid getwid allows Retrieve Embedded Sensitive Data.This issue affects Getwid: from n/a through <= 2.1.2.
Published: 2025-09-22
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Getwid WordPress plugin allows an attacker to retrieve embedded sensitive data that should not be exposed. This results in the leakage of confidential information, compromising data confidentiality. The weakness is a classic example of information exposure (CWE‑201).

Affected Systems

Vendors and products affected by this flaw include the jetmonsters:Getwid WordPress plugin. All installations of Getwid from the product’s inception up to version 2.1.2 are vulnerable. Higher‑than 2.1.2 versions are not affected.

Risk and Exploitability

The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1% suggests the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. The likely attack vector is remote, via a web request that triggers the plugin’s data output functionality, but the description does not explicitly state how the data is retrieved, so the precise exploitation path is inferred rather than confirmed.

Generated by OpenCVE AI on April 30, 2026 at 01:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Getwid plugin version (2.1.3 or newer).
  • If the plugin is not needed, remove or deactivate it entirely.
  • Audit the site for any exposed sensitive data that may have been logged or displayed by the vulnerable plugin and revoke any credentials that may have been inadvertently exposed.

Generated by OpenCVE AI on April 30, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30581 Insertion of Sensitive Information Into Sent Data vulnerability in jetmonsters Getwid allows Retrieve Embedded Sensitive Data. This issue affects Getwid: from n/a through 2.1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in jetmonsters Getwid allows Retrieve Embedded Sensitive Data. This issue affects Getwid: from n/a through 2.1.2. Insertion of Sensitive Information Into Sent Data vulnerability in jetmonsters Getwid getwid allows Retrieve Embedded Sensitive Data.This issue affects Getwid: from n/a through <= 2.1.2.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Tue, 23 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in jetmonsters Getwid allows Retrieve Embedded Sensitive Data. This issue affects Getwid: from n/a through 2.1.2.
Title WordPress Getwid Plugin <= 2.1.2 - Sensitive Data Exposure Vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T01:04:18.097Z

Reserved: 2025-08-27T16:19:53.146Z

Link: CVE-2025-58252

cve-icon Vulnrichment

Updated: 2025-09-23T15:58:36.656Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:16:11.073

Modified: 2026-04-23T15:33:23.277

Link: CVE-2025-58252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T01:30:24Z

Weaknesses