Impact
The YITH WooCommerce Zoom Magnifier plugin contains an unauthenticated data disclosure flaw in all releases up to and including version 2.52.0. This issue, identified as CWE‑497, permits any visitor to a WordPress site to retrieve private information that the plugin stores or generates, thereby violating confidentiality and potentially breaching privacy regulations.
Affected Systems
The vulnerability impacts the YITH WooCommerce Zoom Magnifier plugin developed by YITHEMES. Any WordPress installation that has the plugin at version 2.52.0 or earlier is susceptible, regardless of the underlying WordPress core or theme versions.
Risk and Exploitability
The CVSS score of 5.3 signifies a Medium severity. Because the EPSS score is not available and it is not listed in CISA KEV, the current exploitation probability is unknown, but the flaw does not require authentication. The likely attack vector is that an attacker can send a crafted HTTP request to the plugin’s exposed endpoint to extract sensitive data, making this vector trivial for anyone who can reach the site.
OpenCVE Enrichment