CVE-2021-38314 is an information disclosure vulnerability affecting the Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress. Unauthenticated attackers can exploit predictable AJAX actions to retrieve sensitive site information, including active plugin versions, PHP version, and a hashed combination of the site's authentication keys. Rated Medium severity (CVSS 5.3), this vulnerability has a low attack complexity and requires no user interaction, potentially leading to unauthorized information access. While not listed in CISA's KEV catalog, its high EPSS score (0.916) and FAUCET Risk Score (99/100) indicate a significant likelihood of exploitation, with Nuclei templates available for detection and a single media mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.2.11CPE matchmatch criteria | cpe:2.3:a:redux:gutenberg_template_library_\&_redux_framework:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.