Impact
The vulnerability is an information disclosure flaw that allows an unauthorized user to access embedded sensitive data within the WP Messiah BoomDevs WordPress Coming Soon plugin. It stems from the plugin's failure to properly restrict access to system information, resulting in a CWE‑497 weakness. Attackers could obtain this data by interacting with the plugin through the public web interface, potentially exposing administrative credentials, API tokens, or other confidential configuration details.
Affected Systems
WP Messiah’s BoomDevs WordPress Coming Soon plugin versions up to and including 1.0.4 are affected. The flaw applies to all sites that have installed any version of this plugin prior to 1.0.5.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate severity. The EPSS score of less than 1% suggests that the likelihood of exploitation in the near term is low, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by simply visiting the plugin’s public endpoints, meaning no special credentials or authentication are required. Given the moderate CVSS and low EPSS, the overall risk remains low, but remediation is recommended to prevent potential data leakage.
OpenCVE Enrichment