Impact
The vulnerability in the Essential Plugin Portfolio and Projects plugin allows an attacker to retrieve embedded sensitive data that should not be publicly accessible. Identified as a Sensitive Data Exposure weakness (CWE‑497), the flaw can lead to the disclosure of confidential system information, potentially compromising the confidentiality of the affected WordPress site.
Affected Systems
The issue affects all releases of the Essential Plugin Portfolio and Projects plugin up to and including version 1.5.5. Sites that have installed any of these affected versions of the plugin are at risk. The plugin is commonly used on WordPress installations that display portfolio or project information.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity for this data exposure. The EPSS score of less than 1% suggests that, as of this analysis, the likelihood of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to trigger the plugin’s data retrieval functionality, which may be accessible to users with plugin usage privileges. No privileged escalation is required, but the exposure of sensitive system data is already a non‑negligible threat.
OpenCVE Enrichment