Impact
This vulnerability in the PostX Ultimate‑Post plugin allows an attacker to download or view sensitive information stored by the site. The flaw is a classic data‑exposure weakness (CWE‑497) that permits retrieval of embedded data that should remain confidential. A successful exploitation would cause confidentiality loss for the site’s data but does not compromise code execution or availability.
Affected Systems
WPXPO PostX Ultimate‑Post plugin, any installation whose version is 5.0.3 or earlier. No version higher than 5.0.3 is impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is below 1%, suggesting that the likelihood of automated exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the publicly exposed web interface of the WordPress site, where any user can send a request that triggers the data‑extraction logic. No additional setup or privileged access appears to be required beyond normal public access to the site.
OpenCVE Enrichment