Impact
This vulnerability causes sensitive system information to be exposed to unauthorized users. The flaw is classified as CWE-497. The plugin may inadvertently return embedded sensitive data, potentially revealing configuration details, credentials, or other confidential information that should remain confidential. The impact is limited to confidentiality; there is no immediate compromise of integrity or availability. Attackers gaining access to this data could use it in further attacks.
Affected Systems
WordPress sites that have the honzat Page Manager for Elementor plugin installed with a version of 2.0.5 or earlier are affected. The plugin is available from the honzat vendor and installed through the WordPress plugin interface.
Risk and Exploitability
The CVSS score of 4.3 denotes moderate risk. The EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in CISA KEV. Based on the description, the attack vector is likely unauthenticated access to a plugin endpoint or through standard plugin usage, which does not require special privileges. An attacker could exploit the flaw by sending crafted requests or navigating to specific plugin pages to trigger the data leak.
OpenCVE Enrichment
EUVD