The User Registration plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lock_content_form_handler' and 'display_password_form' function in versions up to, and including, 3.7.3. This makes it possible for unauthenticated attackers to decrypt and view the password protected content.
CVE ID: CVE-2023-3371
CVSS Base Severity: MEDIUM
CVSS Base Score: 5.3
Vendor: wpdevteam
Product: EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor
EPSS Score: 0.16% (probability of being exploited)
EPSS Percentile: 53.53% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)