Impact
WPJAM Basic, a WordPress plugin, allows the disclosure of subscriber sensitive data in all versions up to 7.0.2.1. The flaw follows CWE-1258 and can lead to unintended exposure of personal subscriber information, consequently compromising confidentiality for affected users.
Affected Systems
WordPress sites that have the WPJAM Basic plugin from the vendor denishua installed in version 7.0.2.1 or earlier are affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating moderate‑to‑high impact, and was not listed in the CISA KEV catalog. No EPSS score is published, so the exact exploitation probability is unknown, but the severity suggests attackers could gain valuable subscriber data if they can reach the plugin’s exposed functionality. The likely attack vector involves accessing plugin endpoints or data retrieval mechanisms that inadequately protect subscriber information.
OpenCVE Enrichment