Impact
The vulnerability in the Kevin Pirnie KP Agent Ready WordPress plugin allows an attacker to retrieve embedded sensitive data, exposing confidential information. It is an insertion of Sensitive Information Into Sent Data type flaw, identified as CWE-201. The impact is a compromise of data confidentiality, potentially allowing attackers to view or extract data that should remain private.
Affected Systems
Users running the KP Agent Ready plugin on WordPress installations with a version earlier than 1.2.08 are affected. The plugin appears to be used across various sites, so any WordPress environment that has the vulnerable plugin installed is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely known to be exploited in the wild yet. The likely attack vector is through the plugin's processing of data that contains sensitive information; an attacker may trigger data retrieval via normal or crafted requests to the plugin's endpoints. Successful exploitation would enable the attacker to read sensitive data stored or handled by the plugin.
OpenCVE Enrichment