Impact
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in the WordPress Create by Mediavine plugin, developed by John‑Michael L'Allier, allows an attacker to retrieve embedded sensitive data. The issue affects plugin versions from n/a through 2.6.0. Because the plugin fails to enforce proper access controls, any site visitor can read data intended to be confidential, possibly exposing user details, configuration settings, or other private information.
Affected Systems
WordPress sites that host the Create by Mediavine plugin from John‑Michael L'Allier. Specifically any site running plugin version 2.6.0 or earlier is affected, while sites updated to newer releases are presumed safe.
Risk and Exploitability
The vulnerability scores a CVSS of 5.3, indicating moderate severity, and the EPSS score is below 1%, suggesting a low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attack vector is remote and requires only access to the website’s URL space, with no authentication needed to trigger the exposure.
OpenCVE Enrichment