Impact
The WP EasyCart plugin up to version 5.8.11 contains a sensitive data exposure vulnerability that lets attackers retrieve embedded sensitive information from the data returned by the plugin. This can expose credentials, personal data, or other confidential information that should not be publicly visible.
Affected Systems
The Levelfourdevelopment WP EasyCart WordPress plugin versions 5.8.11 and earlier are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% shows a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, based on the description, it is inferred that the flaw can be exploited remotely by sending a crafted request to the plugin’s endpoints, which can result in the disclosure of sensitive data. Administrators should consider the risk if the plugin is exposed to untrusted users or networks.
OpenCVE Enrichment