Impact
The vulnerability resides in Notivo <= 1.4.2, where unauthenticated users can access or retrieve sensitive data via the plugin. This flaw is classified as Sensitive Data Exposure, allowing attackers to read configuration or user information that should remain private. The weakness is a CWE‑201 flaw, meaning data is exposed with insufficient protection.
Affected Systems
WordPress sites running the VillaTheme Notivo plugin at version 1.4.2 or earlier are affected. The plugin must be updated to at least 1.4.3 to fix the issue.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS data is available, so current exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is unauthenticated, attackers can reach the exposed data from any part of the website that loads the plugin. No special privileges or additional conditions are required beyond normal web access.
OpenCVE Enrichment