Impact
This vulnerability in the Ajax Load More WordPress plugin allows an attacker to retrieve embedded sensitive data from the site through unauthorized means. The flaw enables exposure of system information that should not be publicly visible, effectively granting unauthorized users access to confidential data. The weakness maps to CWE-497, representing an exposed but available field that can be queried by an attacker.
Affected Systems
The affected product is the Ajax Load More plugin developed by Darren Cooney. Versions up to and including 7.6.0.2 are vulnerable, with the issue applying from the first release through 7.6.0.2.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at the time of this analysis. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Based on the plugin’s reliance on AJAX calls, the likely attack vector is remote, where a malicious user submits crafted requests to the plugin’s endpoints without needing privileged access. Successful exploitation would result in the disclosure of sensitive system information.
OpenCVE Enrichment
EUVD