Impact
The TrustedLogin Connector plugin for WordPress has a flaw that allows unauthenticated users to gain access to sensitive data. The vulnerability, classified by CWE‑497, permits disclosure of confidential information that the plugin handles, such as user credentials or other private data. This can compromise confidentiality for anyone who visits the affected site and could lead to account takeover or data leakage.
Affected Systems
The issue affects the TrustedLogin Connector plugin, any WordPress installation using versions 2.0.3 or earlier. No other vendors or products are explicitly implicated.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity risk. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this without authentication by sending requests to plugin endpoints exposed by WordPress, suggesting a remote attack vector that does not require elevated privileges or user credentials.
OpenCVE Enrichment