What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SwitchWP WP Client Reports plugin <= 1.0.16 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SwitchWP WP Client Reports plugin <= 1.0.16 versions.
Explanation of Vulnerability in Simple Terms
WP Client Reports versions up to 1.0.16 expose sensitive information to authenticated users without proper access controls. A logged-in user with low privileges can view data they should not have access to. The vulnerability affects the plugin's information handling and does not allow data modification or system disruption.
What an attacker can do
Read sensitive information they should not have access to as a low-privilege authenticated user.
Potential impact on your site
Confidential client reports or other sensitive plugin data may be exposed to any authenticated user, not just administrators.
Conditions required to exploit
Attacker must have a valid WordPress user account with low-level privileges (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities