Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Retrieve Embedded Sensitive Data.This issue affects SUMO Affiliates Pro: from n/a through <= 11.0.0.
Published: 2025-10-29
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SUMO Affiliates Pro WordPress plugin contains a flaw that enables the retrieval of embedded sensitive data. This results in the exposure of system information to users who are not authorized to view it, classified as CWE‑497 (Inadequate Verification of Data in Excessive Outputs). The CVSS score of 4.3 indicates a moderate severity, but the leakage can provide attackers with details about the site’s configuration or affiliate data without compromising overall system control.

Affected Systems

The affected product is FantasticPlugins’ SUMO Affiliates Pro plugin. All releases from the earliest available version up to and including 11.0.0 are impacted. Every instance of the plugin installed on a WordPress site within this version range is susceptible.

Risk and Exploitability

The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker would need to interact with the plugin’s administrative interface or an exposed endpoint to trigger the data retrieval pathway; this may require authenticated or unauthenticated access depending on the site’s configuration. The impact is limited to the disclosure of sensitive data and does not allow full system compromise.

Generated by OpenCVE AI on April 29, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SUMO Affiliates Pro to the latest version released by FantasticPlugins, where the disclosure issue has been fixed.
  • If an immediate update is not feasible, limit the accessibility of the plugin’s administrative pages by restricting them to trusted administrator roles and disable any features that expose system information to the front‑end.
  • Enforce strict WordPress role‑based permissions so that only users with sufficient privileges can view affiliate data, reducing the likelihood that unauthorized users can trigger the data retrieval path.

Generated by OpenCVE AI on April 29, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 30 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Fantasticplugins
Fantasticplugins sumo Affiliates Pro
Wordpress
Wordpress wordpress
Vendors & Products Fantasticplugins
Fantasticplugins sumo Affiliates Pro
Wordpress
Wordpress wordpress

Wed, 29 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Oct 2025 09:00:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Retrieve Embedded Sensitive Data.This issue affects SUMO Affiliates Pro: from n/a through <= 11.0.0.
Title WordPress SUMO Affiliates Pro plugin <= 11.0.0 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References

Subscriptions

Fantasticplugins Sumo Affiliates Pro
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:26:41.184Z

Reserved: 2025-10-29T03:08:07.244Z

Link: CVE-2025-64228

cve-icon Vulnrichment

Updated: 2025-10-29T14:25:21.600Z

cve-icon NVD

Status : Deferred

Published: 2025-10-29T09:15:44.077

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-64228

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T16:30:15Z

Weaknesses