Impact
The vulnerability is an insertion of sensitive information into sent data in the wowpress.host Fix Media Library plugin, allowing attackers to retrieve embedded sensitive data. This flaw can expose private content managed by WordPress, compromising confidentiality. The weakness is classified as CWE-201, indicating that sensitive information is transmitted improperly. The impact is limited to the exposure of confidential data, with no established path to code execution or denial of service reported.
Affected Systems
The affected product is the Fix Media Library plugin for WordPress from the vendor wowpress.host. Versions from the initial release through and including v2.0 are impacted. Sites installing any version up to and including 2.0 that uses this plugin are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in CISA KEV. Because the description does not specify an attack vector, it is inferred that the flaw could be triggered by a web-based user interacting with the plugin's interfaces, potentially allowing remote exploitation through typical WordPress authentication mechanisms. The risk to confidentiality is moderate and the attack would be remote if the plugin is exposed to untrusted users.
OpenCVE Enrichment