Impact
The vulnerability exists in the eesy_ID2WP – Publish InDesign HTML5 WordPress plugin and permits an attacker to supply malicious values for the id2wp_path query parameter. By manipulating this parameter, an unauthenticated user can cause the plugin to read files outside the intended directory to return their contents. This enables disclosure of sensitive files such as configuration files, private keys, or any other data stored on the server, thereby compromising confidentiality.
Affected Systems
Any installation of the eesy_ID2WP – Publish InDesign HTML5 plugin up to and including version 1.0.3 is affected. The specific product is a WordPress plugin, and all users running a vulnerable version are at risk. The issue is confined to the plugin code and does not impact WordPress core.
Risk and Exploitability
The vulnerability receives a CVSS score of 7.5, representing a high level of severity. With no EPSS score available, the probability of exploitation cannot be quantified, but the absence of a required authentication makes the threat realistic. The attack vector is inferred to be remote over HTTP/HTTPS by submitting crafted requests containing the id2wp_path parameter. The vulnerability is not present in the CISA KEV catalog, yet the lack of authentication combined with high impact justifies immediate attention.
OpenCVE Enrichment