The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed file.
Metrics
Affected Vendors & Products
References
History
Mon, 31 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 29 Mar 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed file. | |
| Title | DAP to Autoresponders Email Syncing <= 1.0 - Unauthenticated Information Exposure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-03-29T07:03:29.710Z
Updated: 2025-03-31T13:19:54.340Z
Reserved: 2025-03-27T00:04:13.307Z
Link: CVE-2025-2840
Updated: 2025-03-31T13:19:49.401Z
Status : Awaiting Analysis
Published: 2025-03-29T07:15:19.317
Modified: 2025-04-01T20:26:30.593
Link: CVE-2025-2840
No data.