CVE-2023-47529

MEDIUM

ThemeIsle Cloud Templates & Patterns collection <= 1.2.2 - Exposure of Sensitive Information via Log File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-47529. PoCs published by RandomRobbieBF.

AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2023-47529, demonstrating sensitive information exposure via a predictable log file path in the Cloud Templates & Patterns collection WordPress plugin. The PoC includes a Nuclei template to detect the vulnerability by fetching the log file and verifying its contents.

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeIsle Cloud Templates & Patterns collection.This issue affects Cloud Templates & Patterns collection: from n/a through 1.2.2.

Exploits (1)

nomisec WORKING POC 1 stars
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2023-47529

This repository contains a functional proof-of-concept for CVE-2023-47529, demonstrating sensitive information exposure via a predictable log file path in the Cloud Templates & Patterns collection WordPress plugin. The PoC includes a Nuclei template to detect the vulnerability by fetching the log file and verifying its contents.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Cloud Templates & Patterns collection WordPress plugin <= 1.2.2
No auth needed
Prerequisites: Target must have the vulnerable plugin installed and the log file must exist at the predictable path
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 5.3
EPSS 0.0097
EPSS Percentile 57.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
ThemeIsle/Cloud Templates & Patterns collection < 1.2.2
themeisle/cloud_templates_\&_patterns_collection < 1.2.3
Published Nov 23, 2023
Tracked Since Feb 18, 2026