Description
Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data.

This issue affects KP Agent Ready: from n/a before 1.2.08.
Published: 2026-09-03
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Kevin Pirnie KP Agent Ready WordPress plugin allows an attacker to retrieve embedded sensitive data, exposing confidential information. It is an insertion of Sensitive Information Into Sent Data type flaw, identified as CWE-201. The impact is a compromise of data confidentiality, potentially allowing attackers to view or extract data that should remain private.

Affected Systems

Users running the KP Agent Ready plugin on WordPress installations with a version earlier than 1.2.08 are affected. The plugin appears to be used across various sites, so any WordPress environment that has the vulnerable plugin installed is at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely known to be exploited in the wild yet. The likely attack vector is through the plugin's processing of data that contains sensitive information; an attacker may trigger data retrieval via normal or crafted requests to the plugin's endpoints. Successful exploitation would enable the attacker to read sensitive data stored or handled by the plugin.

Generated by OpenCVE AI on September 3, 2026 at 20:26 UTC.

Remediation

Vendor Solution

Update the WordPress KP Agent Ready Plugin to the latest available version (at least 1.2.08).


OpenCVE Recommended Actions

  • Update the KP Agent Ready WordPress plugin to version 1.2.08 or newer.
  • If an upgrade is delayed, disable or remove the plugin from the WordPress installation to prevent exposure.
  • After updating, review plugin configuration and any data output mechanisms to ensure no sensitive fields are inadvertently exposed.

Generated by OpenCVE AI on September 3, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issue affects KP Agent Ready: from n/a before 1.2.08.
Title WordPress KP Agent Ready plugin < 1.2.08 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-03T17:20:16.325Z

Reserved: 2026-09-03T16:41:28.560Z

Link: CVE-2026-85307

cve-icon Vulnrichment

Updated: 2026-09-03T17:20:08.207Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:30.963

Modified: 2026-09-03T18:17:35.077

Link: CVE-2026-85307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:30:10Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data