Impact
The vulnerability affects versions of the Payment Forms for Paystack WordPress plugin up to 4.0.5 and allows an attacker to read subscriber sensitive data that should be protected. The weakness enables the exfiltration of personal information such as payment details or personal identifiers that are stored or displayed by the plugin. Consequently, confidentiality of subscriber information is compromised, potentially leading to identity theft or fraud.
Affected Systems
WordPress sites using the kendysond Payment Forms for Paystack plugin with versions 4.0.5 or earlier.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity impact. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers likely need access to the plugin’s administrative interface or other authorized site functions to leverage the data exposure flaw; the attack vector is inferred because it is not explicitly detailed in the CVE description.
OpenCVE Enrichment