What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Nouthemes Leopard - WordPress offload media.This issue affects Leopard - WordPress offload media: from n/a through 2.0.36.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Nouthemes Leopard - WordPress offload media.This issue affects Leopard - WordPress offload media: from n/a through 2.0.36.
Explanation of Vulnerability in Simple Terms
The Leopard WordPress plugin for offloading media files exposes sensitive information to authenticated users. A logged-in user with low privileges can read data they should not have access to, such as configuration details or other users' media metadata. The vulnerability requires a valid WordPress account but no special interaction. Update to a version newer than 2.0.36.
What an attacker can do
Read sensitive data like media metadata or configuration details they should not access.
Potential impact on your site
Unauthorized users can view private media information or site configuration exposed by the plugin.
Conditions required to exploit
Attacker must have a valid WordPress user account with low privileges.
Key dates
External resources
Related vulnerabilities