Impact
This vulnerability is an insertion of sensitive information into sent data flaw in the PremiumBizThemes Simple Price Calculator WordPress plugin, which enables the retrieval of embedded sensitive data without proper authorization checks. The issue is classified as a broken access control problem and directly maps to CWE‑201. It allows an attacker to expose confidential information that should be restricted, potentially compromising user privacy and data confidentiality.
Affected Systems
All WordPress sites that have the PremiumBizThemes Simple Price Calculator plugin Version 1.3 or earlier installed are affected. The vulnerability applies to any installation of this plugin, regardless of the WordPress core version, as long as the plugin version remains ≤ 1.3.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact level, and the EPSS score of less than 1% suggests that the probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, involving HTTP requests to the plugin’s endpoints; the broken access control permits unauthenticated users to retrieve sensitive data, making the exploitation straightforward for anyone who can reach the site.
OpenCVE Enrichment
EUVD