CVE-2022-1186

MEDIUM

WordPress plugin Be POPIA Compliant <1.1.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

The WordPress plugin Be POPIA Compliant exposed sensitive information to unauthenticated users consisting of site visitors emails and usernames via an API route, in versions up to an including 1.1.5.

Scores

CVSS v3 5.3
EPSS 0.0108
EPSS Percentile 61.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
bepopiacompliant/Be POPIA Compliant < 1.1.5
web-x/be_popia_compliant < 1.1.5
Published Apr 19, 2022
Tracked Since Feb 18, 2026