Impact
The Download Media Library plugin contains a flaw that permits a non‑authenticated user to retrieve embedded sensitive system information. This disclosure can reveal configuration details, internal paths, or other data that could aid further attacks, and it is classified as CWE‑497.
Affected Systems
The vulnerability affects the WordPress Download Media Library plugin from any release through version 0.2.1. Users running these or earlier versions are impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk to confidentiality and integrity, while the EPSS score of less than 1% shows a very low probability of active exploitation. It is not listed in the CISA KEV catalog, so no known exploitation campaigns are documented. The likely attack vector is via the plugin’s web interface on a WordPress site, inferred from the plugin’s nature as a web component and the lack of alternative mitigations described in the CVE data. An attacker could exploit the flaw by sending crafted requests to the plugin endpoint, though the exact prerequisites are not specified.
OpenCVE Enrichment