Impact
Unauthenticated vulnerabilities in the iCARRY plugin up to version 2.9 allow attackers to read sensitive information without authentication, resulting in a confidentiality breach. The flaw is identified as CWE-201, representing a flaw that permits disclosure of confidential information.
Affected Systems
The vulnerability affects the iCARRY WordPress plugin, developed by Hassan Fakih, for all installed versions 2.9 and older. Users running these versions on any WordPress site are potentially exposed.
Risk and Exploitability
The CVSS score of 7.5 classifies the weakness as high. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely remote and unauthenticated, as the flaw permits information disclosure without credentials, making it exploitable by any actor who can reach the site.
OpenCVE Enrichment