Impact
The vulnerability allows the exposure of subscriber sensitive data through the WordPress Site Reviews plugin when using versions 8.0.11 or older. This flaw is a type of data disclosure weakness classified as CWE-201, meaning that private information may be incorrectly exposed to unauthorized parties. The impact manifests as unauthorized access to contents that should be protected, potentially compromising user confidentiality.
Affected Systems
Any WordPress site that has installed Gemini Labs Site Reviews plugin version 8.0.11 or earlier is affected. The plugin is provided by Gemini Labs and the vulnerability specifically targets systems running those legacy plugin releases. No further affected product versions are listed.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS data is unavailable, so the exact likelihood of exploitation is unknown, but the vulnerability is listed as not in the CISA KEV catalog. Likely attackers could exploit the flaw by navigating to the review or subscriber pages exposed by the plugin, or by sending crafted requests to the plugin’s endpoints to retrieve data. Because no mitigation is applied, any defined access paths that allow users to view subscriber information may be abused, leading to data leakage.
OpenCVE Enrichment