Impact
The vulnerability permits an attacker to retrieve embedded sensitive data from the Roxnor PopupKit popup-builder-block plugin. This constitutes a CWE‑497 breach of confidentiality, exposing system information that should remain protected. The disclosed data could reveal configuration details or other information that an unauthorized user might exploit to further compromise the WordPress site.
Affected Systems
The affected product is the Roxnor PopupKit popup‑builder‑block plugin for WordPress. All releases from the earliest available version up through 2.1.5 are impacted.
Risk and Exploitability
The CVSS 4.3 score places the weakness in the moderate severity range. Its EPSS score of less than 1% suggests exploitation is unlikely in the near term, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is not explicitly documented but is inferred from the description as involving the plugin’s data‑exposure functionality.
OpenCVE Enrichment