Impact
A flaw in Permalink Manager Lite, identified as CWE‑201, allows the plugin to embed sensitive information into outgoing data streams. This enables an attacker to retrieve data such as passwords or other secrets that should remain confidential, leading to a breach of privacy and potential compromise of the site’s integrity.
Affected Systems
The vulnerability impacts the WordPress plugin Permalink Manager Lite from vendor Maciej Bis for all released versions up to and including 2.5.1.3. Any site running this version without additional safeguards is susceptible.
Risk and Exploitability
The CVSS score of 7.5 marks the flaw as high severity, yet the EPSS score is below 1 %, indicating a low probability of exploitation at present. Because the issue involves data transmission, the likely attack vector is normal plugin usage – a legitimate user or automated system interacting with the plugin can trigger the disclosure. The vulnerability is not listed in CISA’s KEV catalog, so there is no current evidence of widespread, targeted exploitation. Nonetheless, the potential for sensitive data leakage warrants prompt action.
OpenCVE Enrichment
EUVD