Impact
The vulnerability allows an attacker to download arbitrary files from the server by exploiting the Youzify plugin’s insufficient validation of file paths. This can lead to the disclosure of sensitive configuration files, personal data, or credentials, thereby compromising confidentiality.
Affected Systems
This issue affects the Youzify WordPress plugin versions 1.3.7 and earlier. Any WordPress site deploying these plugin versions is potentially vulnerable. The plugin vendor is Youzify.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity. No EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by constructing a malicious URL that points to arbitrary files on the server, typically requiring only publicly accessible access to the site.
OpenCVE Enrichment