Impact
The vulnerability allows an unauthorized user to retrieve embedded sensitive data from the Memberful – Membership Plugin when using versions up to and including 1.81.2. This results in the unintended disclosure of confidential system information, breaching confidentiality and potentially enabling further exploitation. The weakness is classified as CWE‑497 (Exposed Content).
Affected Systems
The affected product is the Memberful – Membership Plugin for WordPress. All releases from the earliest available version through 1.81.2 are impacted; version 1.82.0 and later have the issue fixed.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium impact on confidentiality. The lack of an EPSS score means current exploitation probability is unknown, but the absence from KEV suggests no widespread active exploitation has been reported. The attack vector is likely via the web interface of the WordPress site; a user with access to the site could exploit the plugin to download sensitive data. Due to the disclosure nature of the vulnerability, the primary risk is confidentiality loss rather than code execution or denial of service.
OpenCVE Enrichment