Description
Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.
Published: 2026-07-02
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to read subscriber personal information on WordPress sites that use the Zozothemes Corpkit theme version 1.0.5 or earlier because the theme does not adequately protect subscriber data, a flaw categorized as CWE-201.

Affected Systems

All WordPress installations using the Zozothemes Corpkit theme whose release version is 1.0.5 or older are affected. Sites that have not upgraded the theme beyond this release remain susceptible to the data exposure risk.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate security risk. The EPSS score falls below 1%, suggesting a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector can be inferred to involve an attacker who has web-access to the WordPress site such as authentication are not specified in the available description.

Generated by OpenCVE AI on July 21, 2026 at 12:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Corpkit theme to the latest version that fixes the CWE-201 sensitive data exposure issue.
  • For sites unable to update immediately, enforce role-based access control on subscriber data endpoints, ensuring only administrators can retrieve personal information in accordance with CWE-201 mitigation guidelines.
  • If public routes that expose subscriber data remain, remove or restrict them, firewall requests to these paths until the theme is patched, thereby addressing the CWE-201 issue.

Generated by OpenCVE AI on July 21, 2026 at 12:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Zozothemes
Zozothemes corpkit
Vendors & Products Wordpress
Wordpress wordpress
Zozothemes
Zozothemes corpkit

Thu, 02 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.
Title WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Wordpress Wordpress
Zozothemes Corpkit
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T19:42:34.931Z

Reserved: 2025-12-29T11:19:37.128Z

Link: CVE-2025-69132

cve-icon Vulnrichment

Updated: 2026-07-02T19:42:30.461Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:15:02Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data