Impact
The vulnerability exists in the sizam Rehub WordPress theme and permits an unauthorized user to retrieve embedded sensitive data, thereby compromising the confidentiality of system information. It is a CWE‑497 weakness that can expose configuration details or other internal data. No additional destructive impact such as code execution is claimed in the official description.
Affected Systems
WordPress installations running the sizam Rehub theme version 19.9.9.1 or older are affected. The issue is confined to these theme releases and does not extend beyond them.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV. Based on the description it is inferred that an attacker can exploit the theme through the web interface, requiring access to the WordPress environment that supports the vulnerable theme.
OpenCVE Enrichment