Impact
Missing Authorization vulnerability in WP SYNTEX Polylang plugin allows retrieval of embedded sensitive data, resulting in potential exposure of confidential information.
Affected Systems
The vulnerability affects WP SYNTEX Polylang plugin versions from the current earliest revision through 3.8.7, inclusive. Any WordPress installation running a Polylang version at or below 3.8.7 is potentially impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk. EPSS is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves sending a crafted HTTP request to an unprotected Polylang endpoint that returns sensitive content. Attackers with network access to the site can thus obtain confidential data without needing elevated permissions.
OpenCVE Enrichment