Impact
The vulnerability is an IDOR (CWE-639) in the Photo Gallery, Sliders, Proofing and Themes WordPress plugin that allows any user with a Contributor role or higher to retrieve the stored EXIF metadata for any image on the site, including camera make and model, capture timestamp, and internal identifiers reserved for administrators, thus exposing sensitive information.
Affected Systems
The flaw affects the Photo Gallery, Sliders, Proofing and Themes plugin across all releases before version 4.5.0. Any WordPress installation that uses an affected version of this plugin, regardless of the hosting environment, is vulnerable.
Risk and Exploitability
The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in KEV. Based on the description, it is inferred that an attacker with a Contributor or higher role could target arbitrary image IDs to retrieve metadata, exposing sensitive information. The CVSS score of 2.7 categorizes the issue as low severity.
OpenCVE Enrichment