Impact
The vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows an unauthorized entity to retrieve sensitive system information embedded within the plugin. The flaw, identified as CWE‑497, can result in the disclosure of confidential data that should be protected from non‑privileged access. The impact is the loss of confidentiality and potential exposure of internal configuration or user data that are not meant to be publicly visible.
Affected Systems
ThemeHunk’s Contact Form & Lead Form Elementor Builder plugin, version 2.0.1 and earlier, is affected. WordPress sites that have installed this plugin without applying any updates beyond 2.0.1 are at risk. No specific operating system or WordPress core version constraints are listed, so the vulnerability applies broadly to any site using the impacted plugin version.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity flaw. The EPSS score of <1% suggests that, at present, the likelihood of exploitation is low, and the vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector is remote, through the standard web interface of the WordPress plugin, as the vulnerability enables data retrieval by an unauthorized user who can query the plugin’s data handling pathways. A successful exploit would allow the attacker to disclose sensitive server‑side information that should be restricted.
OpenCVE Enrichment