Impact
The vulnerability in the WP Event SOlution plugin allows an attacker to read commercially sensitive customer data that the plugin processes and stores. It is a classic case of sensitive data exposure, classified as CWE-201. A successful exploit could let an adversary gain knowledge of names, contact details or transaction information that should remain confidential, potentially leading to privacy violations or regulatory non‑compliance.
Affected Systems
WordPress sites that have the Arraytics WP Event SOlution plugin installed at version 4.1.18 or earlier. The fix is to upgrade to at least 4.1.19, the first version with the exposed data handling issue resolved.
Risk and Exploitability
With a CVSS score of 6.5, the flaw is moderately severe. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not currently being actively exploited in the wild. The attack path is likely to involve interaction with the plugin’s administrative interfaces or API endpoints; a user with sufficient privileges or an unauthenticated user with access to those endpoints could trigger the data leak. Because the flaw is a direct read of stored data, an exploit does not require additional conditions beyond accessing the plugin files or endpoints.
OpenCVE Enrichment