Impact
Unauthenticated sensitive data exposure occurs in the Complianz GDPR plugin for WordPress versions 7.5.0 and earlier, allowing an attacker to read confidential configuration or user data without authentication. This flaw is linked to CWE‑497, indicating that the plugin exposes data that should be considered confidential. An attacker who can trigger the vulnerability can retrieve the exposed contents, compromising user privacy and potentially revealing information that could aid further attacks.
Affected Systems
The vulnerability affects WordPress installations running the Complianz plugin from vendors identified as Complianz:Complianz, specifically versions 7.5.0 and below. All WordPress sites using the plugin within this version range are potentially impacted.
Risk and Exploitability
The CVSS score of 5.3 rates this threat as moderate, while an EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, suggesting no widely known or documented exploits. The likely attack vector is an unauthenticated HTTP request that triggers the plugin to expose data, with no additional authentication or privilege requirements.
OpenCVE Enrichment