Impact
The GetGenie plugin for WordPress releases contain a flaw that discloses subscriber data to unauthorized users. This vulnerability allows an attacker to gain access to personal information that should be protected, causing a breach of confidentiality. The weakness is classified as CWE‑497, which indicates that the application does not properly protect data from unauthorized disclosure, leading to a moderate security impact as defined by a CVSS score of 6.5.
Affected Systems
WordPress sites running the GetGenie plugin version 4.4.2 or earlier, maintained by Roxnor. No further product version details are provided beyond the known affected range.
Risk and Exploitability
The vulnerability’s CVSS score of 6.5 signifies a medium-level risk. Attackers can exploit it through the plugin’s exposed mechanisms, most likely by interacting with the plugin endpoint as an authenticated or unauthenticated user. Based on the description, the likely attack vector is interacting with the plugin’s exposed endpoints. Because the EPSS score is not available, the likelihood of exploitation cannot be quantified precisely, and the vulnerability is not currently listed in CISA’s KEV catalog. Nonetheless, sites using this plugin should consider the moderate severity and potential for data leakage.
OpenCVE Enrichment