Impact
This vulnerability allows an unauthenticated attacker to read sensitive information exposed by the Sitemovr WordPress plugin in versions 1.0.1 and earlier. The flaw is a classic data‑exposure weakness, formally identified as CWE‑201. Because authentication controls are bypassed, an attacker could retrieve private data stored or managed by the plugin without needing any credentials. The resulting confidentiality breach could expose personal data, administrative credentials, or configuration secrets housed within the plugin's storage.
Affected Systems
The affected system is the Sitemovr plugin for WordPress, produced by Dawer Drew. All installations of the plugin with a version equal to or less than 1.0.1 are susceptible. No further sub‑version or patch information is provided.
Risk and Exploitability
The CVSS score of 7.5 places this issue in the high severity range, indicating that exploitation could be detrimental to a site’s confidentiality. The EPSS score is not available, so the current exploit probability cannot be quantified, but the lack of any security controls makes the attack trivial once the vulnerable plugin is present. It is not listed in CISA’s KEV catalog, suggesting no widespread known exploitation yet. The likely attack vector is direct, unauthenticated HTTP access to the plugin’s data endpoints.
OpenCVE Enrichment