Impact
The vulnerability in the Uncanny Automator WordPress plugin allows an attacker to retrieve embedded sensitive data from the system. This is a confidentiality breach that occurs when the plugin’s “sensitive data retrieval” functionality is accessed without proper authorization, as identified by CWE-497.
Affected Systems
The flaw affects all releases of the Uncanny Automator plugin from the initial version through any build prior to 6.10.0. Users running any of these versions are susceptible; protection is obtained only by updating to 6.10.0 or later.
Risk and Exploitability
With a CVSS score of 4.3, the vulnerability is considered moderate in severity. The EPSS score of less than 1% suggests that the likelihood of exploitation is low, and the flaw is not listed in the CISA KEV catalog. Nonetheless, an attacker who can persuade an authorized user to hit the vulnerable endpoint—likely via the WordPress administration interface—could gain unauthorized access to sensitive data.
OpenCVE Enrichment