CVE-2021-4428 is an information disclosure vulnerability affecting the what3words Autosuggest Plugin for WordPress, specifically versions up to 4.0.0. This flaw resides in the enqueue_scripts function within the w3w-autosuggest/public/class-w3w-autosuggest-public.php file, allowing remote attackers to extract sensitive information. With a CVSS v3.1 score of 7.5 (HIGH), it presents a significant risk due to its network-based attack vector and low attack complexity, leading to high confidentiality impact without requiring user interaction. While the vulnerability has a high EPSS and FAUCET Risk Score, indicating its potential for exploitation, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. Organizations are advised to upgrade to version 4.0.1 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.1CPE matchmatch criteria | cpe:2.3:a:what3words:autosuggest:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.