Impact
A flaw in the TempTool [Show Current Template Info] WordPress plugin allows an attacker to retrieve sensitive system information that should be confined to the site’s control sphere. The vulnerability is classified as CWE‑497 (Exposed Unintended Data) and enables disclosure of embedded template details that are normally only available to administrators, representing a confidentiality breach.
Affected Systems
WordPress sites that have installed the HappyDevs TempTool [Show Current Template Info] plugin version 1.3.1 or earlier are affected. The issue applies to all releases from the initial version up to and including 1.3.1, regardless of the WordPress core or other plugin versions.
Risk and Exploitability
The CVSS score of 4.3 classifies this flaw as moderate severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a publicly accessible web request to the plugin’s ‘current-template-name’ endpoint; the description does not specify any authentication requirement, so it is inferred that the endpoint may be reachable without credentials.
OpenCVE Enrichment