WordPress WP System Information Plugin Sensitive Data Exposure Vulnerability

Vulnerability

A vulnerability allowing the exposure of sensitive system information to an unauthorized control sphere has been identified in the WP System Information plugin for WordPress. This issue affects versions through 1.5 and allows unauthorized users to retrieve embedded sensitive data that is typically not accessible to them.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, which may be used to exploit other weaknesses in the system.

Remediation

Users are advised to remove and replace the WP System Information plugin, as it has not been updated in over a year and is unlikely to receive further support. Deactivating the plugin does not eliminate the security risk unless a virtual patch is applied.

Added: Sep 22, 2025, 7:30 PM
Updated: Sep 22, 2025, 11:42 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.