Impact
The vulnerability allows sensitive data to be inserted into data sent by the Smart One Click Setup – Complete Demo Import & Export plugin. An attacker could obtain confidential information embedded in exported files or responses. The weakness is a classic sensitive data exposure flaw (CWE-201) that could compromise user credentials or site configuration details. The impact is unauthorized disclosure of confidential data from a WordPress site, potentially affecting site integrity and user privacy.
Affected Systems
WordPress installations running the Smart One Click Setup – Complete Demo Import & Export plugin by Chiranjit Hazarika. All released versions up to and including 1.4.3 are vulnerable. Users who have not upgraded to a newer version or applied a fix are at risk.
Risk and Exploitability
With a CVSS score of 5.3, the flaw is considered medium severity. Although the EPSS score is not available and it is not listed in CISA’s KEV catalog, the vulnerability could potentially be triggered through the plugin’s export/import interface, which is accessible via the WordPress admin dashboard. The likely attack vector is an administrative user initiating an export or an attacker who gains such privileges or injects malicious code that calls the export function. Based on the description, it is inferred that the flaw exploits the lack of hard‑coded restriction to privileged users, making it exploitable in typical malware or credential‑stealing scenarios.
OpenCVE Enrichment