Impact
The vulnerability is an unauthenticated sensitive data exposure that permits any user to read confidential information handled by the KiviCare WordPress plugin. The weakness is identified as CWE-288 and allows attackers to gain unauthorized access to data without needing valid credentials.
Affected Systems
The flaw impacts the Iqonic Design KiviCare plugin for WordPress, specifically versions 4.5.1 and earlier. Websites running those plugin versions are vulnerable.
Risk and Exploitability
The issue has a CVSS score of 7.5 and is not listed in the CISA KEV catalog; its EPSS score is not available. Based on the description, it is inferred that attackers can exploit the flaw by accessing URLs of the site, indicating a network-based, unauthenticated attack vector. The resulting loss of confidentiality exposes sensitive data stored by the plugin.
OpenCVE Enrichment