Impact
The WordPress CF7 Apps plugin contains an insertion of sensitive information into the data that it sends, enabling an attacker to retrieve embedded confidential data when the plugin processes form submissions. This flaw, identified as CWE‑201, is a data leakage issue (Sensitive Data Exposure). It allows unauthorized parties to gain access to sensitive information without local privileges or host compromise, and it is triggered via a normal HTTP request that submits a form.
Affected Systems
Affected are installations of the WPExperts CF7 Apps plugin for WordPress up to and including version 3.7.2; all previous releases are also impacted. The vulnerability is fixed in version 3.8.0 and newer.
Risk and Exploitability
An attacker can exploit the flaw by sending a form submission that includes sensitive data from the plugin’s honeypot or configuration, causing the plugin to transmit that data outwards. Because the attack is performed through the web interface, it does not require any special privileges on the host. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score of 5.3 and the nature of the data leakage make it a notable concern for confidentiality for external adversaries able to reach the site.
OpenCVE Enrichment