What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BogdanFix WP SendFox wp-sendfox allows Retrieve Embedded Sensitive Data.This issue affects WP SendFox: from n/a through <= 1.3.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BogdanFix WP SendFox wp-sendfox allows Retrieve Embedded Sensitive Data.This issue affects WP SendFox: from n/a through <= 1.3.1.
Explanation of Vulnerability in Simple Terms
WP SendFox versions 1.3.1 and earlier expose sensitive information over the network without requiring authentication or user interaction. An attacker can read exposed data by sending a network request to the affected plugin. This vulnerability affects all installations of the plugin up to version 1.3.1.
What an attacker can do
Read sensitive information exposed by the plugin without authentication.
Potential impact on your site
Sensitive data may be exposed to unauthenticated attackers if your site runs WP SendFox ≤1.3.1.
Conditions required to exploit
Network access to the WordPress site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities