Impact
The Bread WordPress plugin lacks an authentication and authorization check on its settings export function, enabling any visitor to trigger an export of all plugin configuration data, including the plaintext PDF protection password. This flaw permits the retrieval of sensitive configuration through a public endpoint, potentially allowing attackers to compromise the site or expose confidential information. The missing authorization is a CWE-862 vulnerability.
Affected Systems
WordPress sites running the Bread plugin from vendor radius314 with versions up to and including 2.9.12 are affected. The vulnerability is present in all releases that contain the export_meeting_list endpoint, specifically the download_settings function registered on the plugins_loaded hook.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability simply by making an unauthenticated HTTP request to the /?export-meeting-list=1 endpoint; no additional credentials or privileges are required. This is a missing authorization weakness (CWE-862).
OpenCVE Enrichment