Impact
This vulnerability involves the incorrect handling of sensitive information by the BulletProof Security plugin for WordPress, identified as CWE-201. The flaw allows the plugin to expose embedded sensitive data within responses sent to users. If exploited, attackers could obtain confidential data such as credentials or configuration details, compromising the confidentiality of the site’s information.
Affected Systems
The affected product is the AITpro BulletProof Security WordPress plugin, with versions from the initial release through 6.9 inclusive. Users running any version up to and including 6.9 are impacted. No specific operating system or WordPress core version is listed; the issue solely concerns the plugin itself.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity risk. The EPSS score of less than 1 % suggests a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the web interface of a WordPress site that has the vulnerable plugin enabled; an attacker who can trigger the plugin’s data handling could retrieve the exposed information. No additional exploitation prerequisites are stated, so successful exploitation would require only that the plugin be active on a publicly reachable site.
OpenCVE Enrichment