Impact
This vulnerability allows an attacker to read subscriber personal information on WordPress sites that use the Zozothemes Corpkit theme version 1.0.5 or earlier because the theme does not adequately protect subscriber data, a flaw categorized as CWE-201.
Affected Systems
All WordPress installations using the Zozothemes Corpkit theme whose release version is 1.0.5 or older are affected. Sites that have not upgraded the theme beyond this release remain susceptible to the data exposure risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate security risk. The EPSS score falls below 1%, suggesting a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector can be inferred to involve an attacker who has web-access to the WordPress site such as authentication are not specified in the available description.
OpenCVE Enrichment