Impact
The vulnerability is an Insertion of Sensitive Information Into Sent Data flaw that allows an attacker to retrieve embedded sensitive data from form submissions. The flaw results in accidental disclosure of confidential information that should not be exposed, potentially compromising user privacy and data integrity.
Affected Systems
The Softaculous FormLayer plugin for WordPress, all releases up to and including version 1.0.6, is affected. Versions 1.0.7 and newer have the fix and are not impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote exploitation via accessible web forms, as the plugin processes user‑submitted data and sends it to external destinations.
OpenCVE Enrichment