Impact
The Yogeta WP Cloud plugin, through version 1.0, does not validate a user-supplied file path before passing it to a file‑read function that runs on a publicly accessible endpoint. The lack of authentication means a path, and the plug‑in will return the contents credentials or configuration information, attackers can exfiltrate sensitive data, leading to information disclosure and a possible compromise of privileged accounts. This flaw (CWE‑552).
Affected Systems
Every installation of the Yogeta WP Cloud WordPress plugin version 1.0 or older is impacted. No specific patch version is mentioned, but any upgrade beyond 1.0 removes the described vulnerability. The vulnerability exists on sites that keep the plugin enabled and expose the public endpoint.
Risk and Exploitability
The flaw can be leveraged remotely without credentials by directing a browser or request tool to the vulnerable endpoint with a crafted file path. The CVSS score of 8.6 reflects high severity, while the EPSS score of less than 1% indicates that, so far, exploitation attempts are rare or not observed. Because the vulnerability is not listed in CISA KEV, the lack of authorization and the ability to read arbitrary files on the server make the risk high for any environment that may expose sensitive files within the upload directory or elsewhere.
OpenCVE Enrichment