Impact
The vulnerability resides in the WPC Admin Columns WordPress plugin version prior to 2.3.4, where an AJAX action lacks proper authorization checks. Users as low as subscribers can trigger this action and read any user, post, or taxonomy term metadata, including sensitive data belonging to administrators. This results in an information disclosure that could reveal confidential configuration, personal data, or administrative credentials.
Affected Systems
WordPress sites that have the WPC Admin Columns plugin installed before version 2.3.4 are impacted. All user roles, including subscribers and lower, can exploit the vulnerable AJAX endpoint to access metadata of any user, post, or term on the platform. The issue applies regardless of site configuration; it is not limited to specific plugins or themes.
Risk and Exploitability
Based on the description, it is inferred that the attacker only needs to be authenticated as a subscriber to exploit the vulnerability, with no additional privileges or complex setup required. The lack of a published EPSS score or KEV listing suggests that widespread exploitation has not been observed yet, but the technical severity remains high due to potential exposure of sensitive data. The risk is elevated for sites where confidential metadata is stored and could lead to privacy violations or aid in further compromise.
OpenCVE Enrichment