Impact
The vulnerability resides in MultiVendorX WooCommerce Product Stock Alert, allowing an attacker to read sensitive system information that should not be exposed. It is a classic data‑exposure flaw (CWE‑497) in which the plugin’s code incorrectly exposes internal details to users without proper authorization.
Affected Systems
All WordPress installations running any version of the MultiVendorX WooCommerce Product Stock Alert plugin up through 3.0.6 are affected, irrespective of other plugins or themes installed.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score (below 1%) suggests that exploit attempts are unlikely but still possible. The vulnerability is not listed in CISA’s KEV catalog. While the attack vector is not explicitly defined in the data, it is inferred from the description that it can be triggered via the plugin’s exposed data retrieval mechanisms, potentially through HTTP requests from an authenticated or even unauthenticated user. The impact is limited to information disclosure, but could aid further attack steps if combined with other weaknesses.
OpenCVE Enrichment