A missing authorization vulnerability in the retrieve teacher Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to obtain partial user data by accessing the API functionality.
CVE ID: CVE-2025-31338
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.9
CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Vendor: SUNNET Technology Co., Ltd.
Product: Wisdom Master Pro
EPSS Score: 0.14% (probability of being exploited)
EPSS Percentile: 35.83% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)