Impact
The vulnerability in the Custom Field Template plugin allows an attacker to retrieve sensitive system information that should not be exposed. As a result, confidential data could be accessed by unauthorized parties, potentially leading to privacy breaches. This weakness is tied to CWE‑497, which represents improper access control that permits information disclosure.
Affected Systems
WordPress sites using the Custom Field Template plugin version 2.7.6 or earlier are affected, as specified by the plugin vendor Hiroaki Miyashita. The vulnerability applies to all installations that have not upgraded beyond version 2.7.6.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact, and the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. It is inferred that the attack can be carried out remotely through the WordPress administration interface or front‑end pages where the plugin is active, allowing an unauthenticated or low‑privilege user to trigger data retrieval.
OpenCVE Enrichment