Impact
The vulnerability allows an unauthenticated attacker to retrieve sensitive data through the WordPress Ultimate Store Kit Elementor Addons plugin. As a result, confidential information stored or processed by the plugin can be exposed, impacting the confidentiality of a website’s data. This weakness corresponds to CWE-497.
Affected Systems
The affected product is Ultimate Store Kit Elementor Addons by BDThemes. Versions up to and including 3.0.5 are impacted. Users running these versions on WordPress sites should treat the plugin as vulnerable until patching to 3.0.7 or later.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity assessment. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is unauthenticated, any user with network access to the site could exploit it. The likely attack vector is remote via the web interface, inferred because no authentication is required.
OpenCVE Enrichment