← back
CVE-2025-31001highCWE-1295

WordPress GTM Kit plugin <= 2.4.0 - Sensitive Data Exposure vulnerability

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
In short

The GTM Kit WordPress plugin up to version 2.4.0 exposes sensitive information through debug messages that shouldn't be visible to users. This allows attackers to retrieve confidential data that could compromise your website's security.

Technical detail

The GTM Kit plugin (≤2.4.0) fails to properly restrict debug output, allowing unauthenticated or low-privileged attackers to access embedded sensitive data through debug messages. The vulnerability stems from insufficient information disclosure controls (CWE-1295), enabling data exfiltration without requiring code execution or elevated privileges.

Summary generated and translated by AI from the official description.
Debug Messages Revealing Unnecessary Information vulnerability in TLA Media GTM Kit gtm-kit allows Retrieve Embedded Sensitive Data.This issue affects GTM Kit: from n/a through <= 2.4.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
TLA Media · GTM Kit