What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sewpafly Post Thumbnail Editor.This issue affects Post Thumbnail Editor: from n/a through 2.4.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sewpafly Post Thumbnail Editor.This issue affects Post Thumbnail Editor: from n/a through 2.4.8.
Explanation of Vulnerability in Simple Terms
Post Thumbnail Editor versions up to 2.4.8 expose sensitive information that can be accessed over the network without authentication. An attacker can retrieve this data directly without needing to log in or interact with a user. The vulnerability does not allow modification or deletion of data, only unauthorized viewing.
What an attacker can do
Read sensitive information from the plugin without logging in.
Potential impact on your site
Sensitive data stored or processed by Post Thumbnail Editor may be visible to unauthenticated visitors.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities