Impact
The Loops & Logic WordPress plugin permits unauthenticated users to invoke a public template‑data action that returns user records and site options that normally require authentication. This flaw allows an attacker to read arbitrary email addresses, user roles, and configuration settings, compromising the confidentiality of site data.
Affected Systems
All installations of the Loops & Logic plugin with a version earlier than 4.3.0 are impacted. The vulnerability affects the Unauthenticated User Data and Site Option Disclosure functionality of the plugin,
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating high severity, while the EPSS score is less than 1%, suggesting a low likelihood of current exploitation. It is not listed in CISA KEV. The absence of authentication control and the ability to retrieve sensitive data make this flaw highly exploitable for sites running the affected plugin version. An attacker only needs to construct a request to the vulnerable endpoint; no further credentials or privileged access are required. The significant for any WordPress site that has the plugin installed below 4.3.0.
OpenCVE Enrichment