Impact
The vulnerability allows unauthenticated users to access sensitive data stored by the Custom CSS and JavaScript plugin. This data exposure can lead to the compromise of user credentials, private configuration values, or other personal information, thereby violating confidentiality. The weakness is classified as CWE‑201, indicating improper handling of sensitive information.
Affected Systems
Affected are sites running WP Zone's Custom CSS and JavaScript plugin version 2.0.16 and earlier. No additional product or version details are provided.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. No EPSS score is available, so the exploitation probability is unknown, and the vulnerability is not listed in CISA's KEV catalog. Because the issue is unauthenticated, an attacker only needs to discover a site that has the vulnerable plugin installed and can then retrieve the exposed data by triggering the plugin’s data retrieval endpoint.
OpenCVE Enrichment