Impact
Insertion of Sensitive Information Into Sent Data allows an attacker to retrieve embedded sensitive data. This vulnerability can expose private information that should remain hidden, potentially compromising user privacy and site integrity. The weakness maps to CWE-201, indicating improper handling of confidential data.
Affected Systems
WordPress sites that use the ColorWay theme from inkthemes.com and run any version up to and including 4.2.3 are vulnerable. This includes all earlier releases, as the issue is flagged for "n/a through <= 4.2.3." Site administrators should verify the theme version and plan an update.
Risk and Exploitability
The CVSS score is 5.8, indicating a moderate risk level. The EPSS score is below 1%, suggesting very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack likely requires the site to run the vulnerable theme and may involve remote users accessing pages that include the leaked data, though the official description does not specify an exact exploit method and therefore the attack vector is inferred.
OpenCVE Enrichment