Description
Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions.
Published: 2026-09-23
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Immediate Patch
AI Analysis

Impact

The TrustedLogin Connector plugin for WordPress has a flaw that allows unauthenticated users to gain access to sensitive data. The vulnerability, classified by CWE‑497, permits disclosure of confidential information that the plugin handles, such as user credentials or other private data. This can compromise confidentiality for anyone who visits the affected site and could lead to account takeover or data leakage.

Affected Systems

The issue affects the TrustedLogin Connector plugin, any WordPress installation using versions 2.0.3 or earlier. No other vendors or products are explicitly implicated.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity risk. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this without authentication by sending requests to plugin endpoints exposed by WordPress, suggesting a remote attack vector that does not require elevated privileges or user credentials.

Generated by OpenCVE AI on September 23, 2026 at 20:01 UTC.

Remediation

Vendor Solution

Update the WordPress TrustedLogin Connector Plugin to the latest available version (at least 2.0.4).


OpenCVE Recommended Actions

  • Upgrade the TrustedLogin Connector Plugin to version 2.0.4 or later.
  • If an upgrade is not immediately possible, disable the plugin to remove the exposed endpoints.
  • Audit the plugin configuration and site permissions to ensure that no data is publicly accessible and review access logs for suspicious activity.

Generated by OpenCVE AI on September 23, 2026 at 20:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions.
Title WordPress TrustedLogin Connector plugin <= 2.0.3 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-23T19:42:21.963Z

Reserved: 2026-09-22T09:18:20.379Z

Link: CVE-2026-95600

cve-icon Vulnrichment

Updated: 2026-09-23T19:06:06.887Z

cve-icon NVD

Status : Deferred

Published: 2026-09-23T19:19:53.073

Modified: 2026-09-23T20:17:25.247

Link: CVE-2026-95600

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T20:15:09Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere