Description
Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions.
Published: 2026-09-30
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in Notivo <= 1.4.2, where unauthenticated users can access or retrieve sensitive data via the plugin. This flaw is classified as Sensitive Data Exposure, allowing attackers to read configuration or user information that should remain private. The weakness is a CWE‑201 flaw, meaning data is exposed with insufficient protection.

Affected Systems

WordPress sites running the VillaTheme Notivo plugin at version 1.4.2 or earlier are affected. The plugin must be updated to at least 1.4.3 to fix the issue.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. No EPSS data is available, so current exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is unauthenticated, attackers can reach the exposed data from any part of the website that loads the plugin. No special privileges or additional conditions are required beyond normal web access.

Generated by OpenCVE AI on September 30, 2026 at 15:55 UTC.

Remediation

Vendor Solution

Update the WordPress Notivo plugin to the latest available version (at least 1.4.3).


OpenCVE Recommended Actions

  • Update the Notivo plugin to version 1.4.3 or later.
  • Restrict plugin access to authenticated administrators only by disabling or limiting relevant endpoints.
  • Audit the site for any stored sensitive data that may have been exposed and cleanse or reconfigure as necessary.

Generated by OpenCVE AI on September 30, 2026 at 15:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions.
Title WordPress Notivo plugin <= 1.4.2 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T13:27:08.648Z

Reserved: 2026-09-24T10:23:19.164Z

Link: CVE-2026-97261

cve-icon Vulnrichment

Updated: 2026-09-30T13:20:07.488Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T13:17:37.400

Modified: 2026-09-30T14:18:16.367

Link: CVE-2026-97261

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T16:00:15Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data