Impact
This vulnerability in the Arraytics WP Event Solution plugin (versions up through 4.1.25) enables an unauthenticated attacker to retrieve embedded sensitive data from the system. The flaw arises from improper protection of sensitive information, aligning with information disclosure weaknesses. An attacker could gain access to confidential system details, which may lead to further compromise if sensitive data includes credentials or configuration details.
Affected Systems
Affected systems include any WordPress installation using the WP Event Solution plugin before version 4.1.26. The plugin is distributed under the Arraytics banner, and all versions marked as n/a through 4.1.25 are vulnerable. Administrators should verify plugin version and upgrade accordingly.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate impact, and the EPSS score is not available, so the current likelihood of exploitation is uncertain. While the vulnerability is not listed in CISA's KEV catalog, the potential for unauthorized data exposure exists via web requests to the plugin's endpoints. Administrators should treat this as a medium risk that warrants timely patching.
OpenCVE Enrichment