Impact
The Context Blog theme for WordPress contains an issue in its modal‑popup component that, when a post ID is supplied, returns the full content of posts that are password‑protected. Because the page does not require authentication, an attacker can retrieve sensitive material that is intended to remain confidential. The weakness is a classic information‑disclosure flaw and is classified as CWE‑200.
Affected Systems
WordPress sites that are running Context Blog version 1.3.5 or earlier are vulnerable. All installations that include any of the earlier versions listed in the theme’s changelog are potentially affected.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate impact if less than 1 % suggests that the vulnerability is not widely exploited in a post ID, requiring no user authentication.
OpenCVE Enrichment