Impact
The reported flaw in the Nitesh Ultimate Auction plugin allows inclusion of sensitive information in data transmitted by the plugin. An attacker who can trigger the vulnerable functionality may be able to retrieve confidential data embedded in the response. This flaw is categorized as a medium‑severity issue (CVSS 5.3) and primarily threatens confidentiality. The CVE description does not state any effects on integrity or availability.
Affected Systems
The issue affects any WordPress site running the Ultimate Auction plugin version 4.3.3 or earlier. The plugin is provided by Nitesh and widely used in WordPress auction implementations.
Risk and Exploitability
The EPSS score is less than 1%, indicating a low probability of exploitation at present, and the vulnerability is not in the CISA KEV catalog. The likely attack vector appears to be an exposed plugin endpoint that can be accessed without authentication, but this is inferred because the description does not specify the exact method of exploitation. Successful exploitation would expose sensitive data, but there is no evidence from the available information that integrity or availability could be affected.
OpenCVE Enrichment