Description
Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.
Published: 2026-10-06
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Patch
AI Analysis

Impact

This vulnerability allows an unauthenticated attacker to read sensitive information exposed by the Sitemovr WordPress plugin in versions 1.0.1 and earlier. The flaw is a classic data‑exposure weakness, formally identified as CWE‑201. Because authentication controls are bypassed, an attacker could retrieve private data stored or managed by the plugin without needing any credentials. The resulting confidentiality breach could expose personal data, administrative credentials, or configuration secrets housed within the plugin's storage.

Affected Systems

The affected system is the Sitemovr plugin for WordPress, produced by Dawer Drew. All installations of the plugin with a version equal to or less than 1.0.1 are susceptible. No further sub‑version or patch information is provided.

Risk and Exploitability

The CVSS score of 7.5 places this issue in the high severity range, indicating that exploitation could be detrimental to a site’s confidentiality. The EPSS score is not available, so the current exploit probability cannot be quantified, but the lack of any security controls makes the attack trivial once the vulnerable plugin is present. It is not listed in CISA’s KEV catalog, suggesting no widespread known exploitation yet. The likely attack vector is direct, unauthenticated HTTP access to the plugin’s data endpoints.

Generated by OpenCVE AI on October 6, 2026 at 06:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Sitemovr plugin to a version newer than 1.0.1.
  • Disable the plugin entirely if an immediate update is not possible, ensuring that its data endpoints are not exposed.
  • Review WordPress and server logs for any evidence of unauthorized data access and archive findings for future analysis.

Generated by OpenCVE AI on October 6, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.
Title WordPress Sitemovr plugin <= 1.0.1 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-06T05:14:51.195Z

Reserved: 2026-04-21T12:35:51.613Z

Link: CVE-2026-41563

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T06:17:01.530

Modified: 2026-10-06T06:17:01.530

Link: CVE-2026-41563

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T06:30:08Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data