Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in o2oe E-Invoice App Malaysia einvoiceapp-malaysia allows Retrieve Embedded Sensitive Data.This issue affects E-Invoice App Malaysia: from n/a through <= 1.3.0.
Published: 2025-12-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the E‑Invoice App Malaysia WordPress plugin up to version 1.3.0, allowing an attacker to retrieve embedded sensitive system information. The flaw is an indirect data exposure weakness (CWE‑497) that could let an unauthorized user gain access to confidential information that should be restricted to privileged roles. The potential impact is the compromise of data confidentiality, as the exposed information may include internal identifiers, configuration details, or personal data related to invoicing processes.

Affected Systems

Affected systems are installations of the WordPress plugin E‑Invoice App Malaysia released by o2oe, specifically versions from the earliest available release through 1.3.0. Users running any version of the plugin in that range are at risk. The description does not enumerate additional sub‑versions or granular release dates beyond the <= 1.3.0 cutoff.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is reported as less than 1%, suggesting a very low probability that the vulnerability is actively exploited in the wild, and it is not listed in the CISA KEV catalog. Nevertheless, the vulnerability can be triggered by any user with access to the plugin’s administrative interface, or potentially by a publicly reachable endpoint if the plugin exposes data via HTTP. While the exact attack vector is not detailed, it is inferred that unauthorized access is possible through the plugin’s backend or exposed API. The risk remains significant for environments that process sensitive invoicing data.

Generated by OpenCVE AI on April 29, 2026 at 15:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the E‑Invoice App Malaysia plugin to a version newer than 1.3.0, if available; this is the recommended official patch.
  • If an upgrade is not immediately feasible, disable the plugin or remove it from production instances to prevent data exposure.
  • Restrict administrative access to the plugin’s backend by applying role‑based access controls or IP‑based restrictions, ensuring only trusted users can invoke plugin functionality.

Generated by OpenCVE AI on April 29, 2026 at 15:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in o2oe E-Invoice App Malaysia einvoiceapp-malaysia allows Retrieve Embedded Sensitive Data.This issue affects E-Invoice App Malaysia: from n/a through <= 1.1.0. Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in o2oe E-Invoice App Malaysia einvoiceapp-malaysia allows Retrieve Embedded Sensitive Data.This issue affects E-Invoice App Malaysia: from n/a through <= 1.3.0.
Title WordPress E-Invoice App Malaysia plugin <= 1.1.0 - Sensitive Data Exposure vulnerability WordPress E-Invoice App Malaysia plugin <= 1.3.0 - Sensitive Data Exposure vulnerability

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared O2oe
O2oe e-invoice App Malaysia
Wordpress
Wordpress wordpress
Vendors & Products O2oe
O2oe e-invoice App Malaysia
Wordpress
Wordpress wordpress

Tue, 30 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in o2oe E-Invoice App Malaysia einvoiceapp-malaysia allows Retrieve Embedded Sensitive Data.This issue affects E-Invoice App Malaysia: from n/a through <= 1.1.0.
Title WordPress E-Invoice App Malaysia plugin <= 1.1.0 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References

Subscriptions

O2oe E-invoice App Malaysia
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:33.801Z

Reserved: 2025-12-29T11:18:04.294Z

Link: CVE-2025-68988

cve-icon Vulnrichment

Updated: 2025-12-30T21:40:21.532Z

cve-icon NVD

Status : Deferred

Published: 2025-12-30T11:15:57.450

Modified: 2026-04-27T19:16:39.947

Link: CVE-2025-68988

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T15:15:14Z

Weaknesses