Impact
The vulnerability is an insertion of sensitive information into data transmitted by the Mindio Magic MCP WordPress plugin, which allows an attacker to retrieve embedded sensitive data. This flaw is based on improper handling of confidential data and is classified as CWE-201, leading to a confidentiality compromise if exploited.
Affected Systems
The affected product is the WordPress Mindio Magic MCP plugin from farvisun, versions up to and including 0.5.6. The vendor recommends updating to version 0.7.1 or later to remediate the issue.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is normal use of the plugin in a WordPress site; an attacker who can load the plugin can extract sensitive information embedded in the plugin’s data outputs.
OpenCVE Enrichment