Impact
The vulnerability in Pixelite’s Events Manager plugin allows an attacker to retrieve embedded sensitive data that should not be exposed. The flaw results from confidential information being inserted into HTTP responses, directly breaching confidentiality without providing code execution or denial‑of‑service capabilities.
Affected Systems
All WordPress sites that host Pixelite Events Manager v7.4.5 or earlier are affected. The vulnerability applies to every release from the earliest build through 7.4.5 inclusive, regardless of WordPress core version.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to trigger the plugin’s data handling via its public interfaces, such as HTTP endpoints or user‑initiated actions, which can be performed locally or remotely depending on site configuration. The overall risk remains moderate, and patching is the most effective mitigation.
OpenCVE Enrichment