What the vulnerability does
01Description
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
Explanation of Vulnerability in Simple Terms
Custom CSS and JavaScript versions up to 2.0.16 leak sensitive information in outbound data. An unauthenticated attacker on the network can intercept or observe this data without user interaction. The plugin exposes details that should remain confidential, potentially revealing site configuration or user information to passive observers.
What an attacker can do
Intercept or observe sensitive information sent by the plugin in network traffic.
Potential impact on your site
Sensitive site or user data may be exposed to network-level eavesdropping if HTTPS is not enforced.
Conditions required to exploit
Network access to observe outbound traffic; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities