Impact
pH7Builder before version 18.6.0 contains a hard‑coded API key in Tool.class.php, a weakness classified as CWE-798. By sending an HTTP request with a spoofed Host header and the value private_api_key=dev772277, an attacker can bypass the API access checks. This allows the retrieval of member emails, IP addresses, phone numbers, and bank account fields without any authentication.
Affected Systems
The vulnerability affects installations of pH7Builder (pH7 Social Dating CMS) from all releases before 18.6.0, including the 18.5.x branch and earlier. Any site running that CMS with the default configuration is susceptible.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the vulnerability is exploitable over the network by directing crafted HTTP requests to the application. With no authentication required and no additional system configuration needed, an attacker can obtain highly sensitive personal data. The EPSS value is not available, but the lack of KEV listing suggests it has not yet been widely exploited in the wild.
OpenCVE Enrichment