Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in sizam REHub Framework rehub-framework allows Retrieve Embedded Sensitive Data.This issue affects REHub Framework: from n/a through < 19.9.9.4.
Published: 2026-01-22
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The REHub Framework plugin contains an information disclosure flaw that allows an attacker to retrieve embedded sensitive data from the system. The vulnerability arises because the plugin fails to enforce proper access controls on its data handling routines, exposing confidential system information. This flaw results in a moderate confidentiality breach, as the attacker can obtain data that should be restricted to authorized users. The likely attack vector is inferred to be via web requests to vulnerable plugin endpoints or exposed configuration files, as the plugin is a WordPress component and data is accessible through its interface.

Affected Systems

Affected are WordPress sites running the sizam REHub Framework plugin. All versions earlier than 19.9.9.4 are vulnerable, including 19.9.9.3 and any previous releases. Sites that have not yet migrated to the patched version are therefore at risk.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk level for confidentiality impact. The EPSS score of less than 1% suggests that the likelihood of exploitation is low at present, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an exposed plugin interface or local access; while the exploit does not necessarily grant full control of the system, it can provide attackers with useful sensitive information that could aid further attacks.

Generated by OpenCVE AI on April 29, 2026 at 12:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the REHub Framework plugin to version 19.9.9.4 or later to remove the information disclosure flaw.
  • Disable the REHub Framework plugin or its data‑exposure endpoints until the upgrade is applied, ensuring that no sensitive data is accessible through the web interface.
  • Restrict access to the plugin’s administrative pages and APIs to a minimal set of trusted users and apply role‑based access controls to limit exposure.

Generated by OpenCVE AI on April 29, 2026 at 12:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 28 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 23:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in sizam REHub Framework rehub-framework allows Retrieve Embedded Sensitive Data.This issue affects REHub Framework: from n/a through < 19.9.9.4.
Title WordPress REHub Framework plugin < 19.9.9.4 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T19:35:33.524Z

Reserved: 2025-10-24T14:26:32.477Z

Link: CVE-2025-63051

cve-icon Vulnrichment

Updated: 2026-01-26T21:56:08.526Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:15:59.907

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-63051

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T13:00:06Z

Weaknesses