Impact
The REHub Framework plugin contains an information disclosure flaw that allows an attacker to retrieve embedded sensitive data from the system. The vulnerability arises because the plugin fails to enforce proper access controls on its data handling routines, exposing confidential system information. This flaw results in a moderate confidentiality breach, as the attacker can obtain data that should be restricted to authorized users. The likely attack vector is inferred to be via web requests to vulnerable plugin endpoints or exposed configuration files, as the plugin is a WordPress component and data is accessible through its interface.
Affected Systems
Affected are WordPress sites running the sizam REHub Framework plugin. All versions earlier than 19.9.9.4 are vulnerable, including 19.9.9.3 and any previous releases. Sites that have not yet migrated to the patched version are therefore at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk level for confidentiality impact. The EPSS score of less than 1% suggests that the likelihood of exploitation is low at present, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an exposed plugin interface or local access; while the exploit does not necessarily grant full control of the system, it can provide attackers with useful sensitive information that could aid further attacks.
OpenCVE Enrichment