Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in xtemos WoodMart woodmart allows Retrieve Embedded Sensitive Data.This issue affects WoodMart: from n/a through <= 8.3.9.
Published: 2026-03-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

WoodMart themes for WordPress up to and including version 8.3.9 contain an issue that can expose sensitive system information to an unauthorized control sphere. The vulnerability allows retrieval of embedded sensitive data from the theme’s configuration or files, potentially leaking internal paths, configuration values, or other private information. The weakness is classified as CWE-497, indicating an improper handling of sensitive data that may result in disclosure. The official description states that the issue "allows Retrieve Embedded Sensitive Data," but does not specify the exact data contents or methods of extraction. Nonetheless the impact is clear: a successful exploitation would provide attackers with information that could aid further attacks or compromise user privacy.

Affected Systems

The affected product is the WoodMart theme from xtemos. All versions from an unspecified initial release (n/a) through 8.3.9 are impacted. No specific higher or lower bounds are given beyond "<= 8.3.9," so any installation of WoodMart 8.3.9 or earlier should be considered vulnerable. Versions newer than 8.3.9 are presumed not to contain the flaw according to the vendor’s stated advisory.

Risk and Exploitability

The CVSS score for this vulnerability is 5.3, placing it in the medium severity range. The EPSS score is reported as less than 1%, indicating a low probability that exploitation is occurring or that exploits are widespread. It is not listed in the CISA Known Exploited Vulnerabilities catalog, further supporting a lower exploitation likelihood. Attack vector details are not explicitly stated; the description suggests that the vulnerability could be leveraged by an entity that can read the theme’s point-of-entry files or settings. Based on the disclosed nature of the flaw, the likely attack path would involve authenticated access to the theme’s backend or privileged file system access, but this is inferred rather than directly confirmed in the provided data. Therefore, while the risk to affected sites is moderate, the likelihood of a real-world exploit at present is low.

Generated by OpenCVE AI on March 17, 2026 at 17:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Confirm the currently installed WoodMart theme version by reviewing the WordPress theme editor or the "Appearance → Themes" screen.
  • If the version is 8.3.9 or earlier, update the WoodMart theme to the latest available release, which is 8.4.0 or newer.
  • Verify that the update includes the fix for the sensitive data exposure issue by consulting the vendor’s changelog or patch notes.
  • After the update, audit the theme’s configuration files and logs to ensure no residual sensitive data is exposed.

Generated by OpenCVE AI on March 17, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 17 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Xtemos
Xtemos woodmart
Vendors & Products Wordpress
Wordpress wordpress
Xtemos
Xtemos woodmart

Fri, 13 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in xtemos WoodMart woodmart allows Retrieve Embedded Sensitive Data.This issue affects WoodMart: from n/a through <= 8.3.9.
Title WordPress WoodMart theme <= 8.3.9 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References

Subscriptions

Wordpress Wordpress
Xtemos Woodmart
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:16:10.955Z

Reserved: 2026-03-12T11:11:14.585Z

Link: CVE-2026-32405

cve-icon Vulnrichment

Updated: 2026-03-17T13:16:15.890Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-13T19:54:56.883

Modified: 2026-03-17T14:16:16.733

Link: CVE-2026-32405

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-23T12:03:57Z

Weaknesses