Impact
The REHub theme for WordPress allows an unauthenticated attacker to retrieve the full content of password-protected posts through the ajax_action_re_getfullcontent endpoint. Because the endpoint does not sufficiently restrict which posts are returned, an attacker can read content they should not have access to, resulting in the unauthorized disclosure of private or sensitive information.
Affected Systems
The vulnerability affects all releases of the REHub – Price Comparison, Multi Vendor Marketplace WordPress Theme up to and including version 19.9.7, released by sizam. Users who have installed any of these versions on their WordPress sites are potentially impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, and the EPSS score of < 1% shows that the likelihood of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated web request to the exposed AJAX action; an attacker does not need prior authentication or special privileges to trigger the information leak.
OpenCVE Enrichment
EUVD