Impact
A vulnerability in Chouby Polylang and Polylang Pro plugins up to version 3.8.5 exposes sensitive system information to an unauthorized control sphere, allowing the retrieval of embedded sensitive data. An attacker with access to the affected WordPress installation can exploit the plugin to read data that should not be publicly or externally available. The weakness is classified as CWE-497, indicating information disclosure beyond the intended scope.
Affected Systems
WordPress installations that run the Polylang plugin from Chouby at version 3.8.5 or earlier are affected. The issue is fixed in later releases, so any site using a post-3.8.5 version is no longer vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity. An EPSS score of less than 1% shows probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the WordPress administration interface or actions involving contributors, implying that an attacker would need access to a WordPress site that hosts the vulnerable plugin. It is inferred from the description that the attack would require either contributor privileges or the ability to manipulate contributor data.
OpenCVE Enrichment