What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Marketing Fire, LLC Widget Options - Extended.This issue affects Widget Options - Extended: from n/a through 5.1.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Marketing Fire, LLC Widget Options - Extended.This issue affects Widget Options - Extended: from n/a through 5.1.0.
Explanation of Vulnerability in Simple Terms
Widget Options - Extended through version 5.1.0 exposes sensitive information to authenticated users. A logged-in user with low privileges can access data they should not be able to view. The vulnerability does not allow modification or deletion of data, only unauthorized reading. Update to a version newer than 5.1.0 to resolve this issue.
What an attacker can do
Read sensitive data they should not have access to.
Potential impact on your site
Authenticated users can view private or restricted information not intended for their role.
Conditions required to exploit
Attacker must be logged in with a low-privilege account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities