Impact
The WordPress WP Social Ninja plugin versions up to 4.3.0 suffers from an unauthenticated sensitive data exposure flaw. Attackers can retrieve confidential information accessed or stored by the plugin, compromising data confidentiality. The vulnerability maps to CWE-497, which describes the exposure of sensitive information.
Affected Systems
Any WordPress installation that includes the WP Social Ninja plugin by Mahmudul Hasan Arif and is running version 4.3.0 or earlier is affected. The vendor recommends updating to 4.3.1 or later to remediate the issue. No other products are listed as impacted by this CVE.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while an EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not present in the CISA KEV catalog. The attack vector is inferred to be unauthenticated access to the plugin’s exposed data paths; an attacker who can reach the WordPress site could gain sensitive data.
OpenCVE Enrichment