Impact
The WordPress Motors plugin contains a Vulnerability that allows an attacker to retrieve sensitive information that should not be transmitted within the plugin’s output. This is an insertion of sensitive data into sent content, classified under CWE‑201, and has a CVSS score of 6.9 meaning it can lead to moderate confidentiality impact.
Affected Systems
The affected product is StylemixThemes’ WordPress Motors plugin for WordPress. All versions from any release prior to 1.4.125, including up to and including 1.4.124, are vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate risk profile. The EPSS score is not available, so the probability of exploitation is unknown, and it is not listed in CISA’s KEV catalog. Based on the functionality of the plugin, the likely attack vector is remote via web requests to the site; the vulnerability is exploitable without local access, so any user who can interact with the plugin’s output could potentially retrieve the leaked data.
OpenCVE Enrichment