Impact
The WordPress BSK PDF Manager plugin has a vulnerability that permits an attacker to retrieve embedded sensitive data from the plugin, exposing confidential system information. The flaw stems from improper access control enforcement and is classified as CWE-497, which involves missing authorization checks. The result is that confidential data may be accessed by unauthorized parties, potentially compromising confidentiality and violating data protection requirements.
Affected Systems
The affected product is the bannersky BSK PDF Manager WordPress plugin, versions up through 3.7.2. No other version information is disclosed. Any WordPress site using the plugin at or below that version is at risk.
Risk and Exploitability
The CVSS score is 5.3, which indicates a medium severity, and the EPSS score is less than 1%, pointing to a low exploitation probability. Nevertheless, the vulnerability remains exploitable by unauthenticated users who can retrieve embedded sensitive data through the plugin’s publicly accessible endpoints. No authentication is required, so any user who can reach the WordPress site may take advantage of the flaw. The KEV finding that the vulnerability is not yet listed in the CISA catalog does not diminish the risk it poses.
OpenCVE Enrichment