Impact
The vulnerability allows an attacker to access sensitive subscriber information stored by the SureFeedback Client Site plugin. The flaw exists in all versions up to and including 1.2.12, leading to a disclosure of confidential data such as personal details, subscription status, or other private information managed by the plugin.
Affected Systems
WordPress installations that use the Brainstorm Force SureFeedback Client Site plugin version 1.2.12 or earlier are affected. This includes any site that has not upgraded to the latest version after the vulnerability was disclosed.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity. While an EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the presence of a direct data exposure flaw suggests that an attacker could exploit it remotely by interacting with exposed plugin endpoints. The exact attack vector is not explicitly documented, but the plugin’s functionality indicates that accessing certain URLs or submitting requests could trigger the disclosure.
OpenCVE Enrichment