Executive brief
KP Agent Ready is a WordPress plugin used to manage client interactions and website readiness. The plugin inadvertently embeds sensitive information (such as passwords, emails, or API tokens) in data sent over the network, allowing an unauthenticated attacker to intercept and retrieve this private information. This could lead to unauthorized access to accounts and systems managed through the plugin.
Technical details
This vulnerability is a sensitive data exposure issue (CWE-201: Insertion of Sensitive Information Into Sent Data) in the KP Agent Ready WordPress plugin. The plugin embeds sensitive information such as passwords, emails, and other private data within network traffic or responses without proper redaction or encryption. An unauthenticated, network-adjacent attacker can intercept this transmitted data to retrieve the embedded sensitive information. No authentication or special privileges are required to exploit this vulnerability. The issue is resolved in version 1.2.08 and later.
Affected products
- Kevin Pirnie KP Agent Ready before 1.2.08
Timeline
- 2026-09-03: disclosed: Published by Patchstack
- 2026-09-03: patched: Version 1.2.08 released