Impact
The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin before version 3.7.1 contains a REST route that returns stored account data. This route lacks an authorization check, so anyone who can reach the endpoint can retrieve the connected service’s API secret and account details. The exposed secret can be used to disconnect the plugin’s integration with the service, potentially disabling the generation of legal pages and compromising the site’s compliance framework.
Affected Systems
WordPress sites running the "Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates" plugin, any version earlier than 3.7.1. Moderately broad impact because the plugin is widely installed, but only versions prior to 3.7.1 are vulnerable. No specific OS or additional product versions are required to exploit the flaw.
Risk and Exploitability
The flaw allows unauthenticated readers to obtain confidential API credentials via a straightforward HTTP request to a REST endpoint. The EPSS score is not available and the vulnerability is not listed in KEV, suggesting no large‑scale exploitation has been reported to date. Nonetheless, once discovered, the attack can be executed with minimal effort, and the lack of authentication means anyone on the internet could harvest secrets from an affected site.
OpenCVE Enrichment