What the vulnerability does
01Description
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
Explanation of Vulnerability in Simple Terms
WP Event Solution versions up to 4.1.18 expose sensitive information in outbound data sent by the plugin. An attacker with low-level site access can trigger requests that leak confidential details. The vulnerability does not allow data modification or system unavailability, but exposed information could be used in follow-up attacks.
What an attacker can do
Read sensitive information included in data the plugin sends over the network.
Potential impact on your site
Confidential data (API keys, tokens, user details) may be exposed to attackers with basic site access.
Conditions required to exploit
Attacker needs a low-privilege account on the WordPress site; no user interaction required.
Key dates
External resources
Related vulnerabilities