Impact
The GetGenie plugin version 4.4.1 and older contain an unauthenticated sensitive data exposure flaw that permits attackers to read personal or system data that the plugin stores or returns. By sending unauthenticated HTTP to the plugin's endpoints, an attacker can retrieve information such as user credentials, configuration settings, or other sensitive content, compromising confidentiality and potentially enabling further attacks. This weakness is classified as CWE‑201, a direct result of insufficient access control.
Affected Systems
All WordPress installations using the Wpmet GetGenie plugin version 4.4.1 or older are affected. The vulnerability applies to any site that has the plugin active, regardless of role privileges, and is present across typical WordPress environments.
Risk and Exploitability
The CVSS score of 6.5 classifies the risk as moderate, while the EPSS score below 1% indicates a very low likelihood of exploitation at this time. The vulnerability is not listed in CISA's KEV catalog. The attack vector is inferred to be remote, through unauthenticated requests to the plugin's exposed API or administrative pages, since no authentication requirement is stated in the description.
OpenCVE Enrichment