Impact
The Create by Mediavine plugin for WordPress contains an unauthenticated vulnerability that allows an attacker to read sensitive data. The flaw exists in all plugin versions up to and including 2.5.3, and the plugin lacks proper restrictions on data visibility. As a result, any visitor can obtain data that is intended to be confidential, potentially exposing user information, configuration details, or other private data.
Affected Systems
WordPress sites that host the Create by Mediavine plugin from the mischiefmarmot vendor, specifically versions 2.5.3 or earlier. Sites that have updated to newer releases are presumed not to be affected by this issue.
Risk and Exploitability
The vulnerability scores a CVSS of 5.3, indicating moderate severity, and the EPSS score is below 1%, suggesting a low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA's KEV catalog. The attack vector is likely remote, requiring only access to the website’s URL space; no authentication is needed to trigger the exposure.
OpenCVE Enrichment