What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exeebit phpinfo() WP.This issue affects phpinfo() WP: from n/a through 5.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exeebit phpinfo() WP.This issue affects phpinfo() WP: from n/a through 5.0.
Explanation of Vulnerability in Simple Terms
The phpinfo() WP product exposes sensitive server and PHP configuration details to unauthenticated visitors. An attacker can access this information over the network without any special privileges or user interaction. The exposed data may include database credentials, API keys, file paths, and other system details that could aid further attacks.
What an attacker can do
Read sensitive server configuration and PHP environment details without authentication.
Potential impact on your site
Attackers can gather reconnaissance data about your server setup, potentially exposing credentials and system paths.
Conditions required to exploit
Network access to the affected site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities