Home

Description

Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it. This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30.

PUBLISHED Reserved 2025-08-27 | Published 2025-09-23 | Updated 2025-10-01 | Assigner Patchstack




MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-201 Insertion of Sensitive Information Into Sent Data

Product status

Default status
unaffected

6.8 (custom)
affected

6.7 (custom)
affected

6.6 (custom)
affected

6.5 (custom)
affected

6.4 (custom)
affected

6.3 (custom)
affected

6.2 (custom)
affected

6.1 (custom)
affected

6.0 (custom)
affected

5.9 (custom)
affected

5.8 (custom)
affected

5.7 (custom)
affected

5.6 (custom)
affected

5.5 (custom)
affected

5.4 (custom)
affected

5.3 (custom)
affected

5.2 (custom)
affected

5.1 (custom)
affected

5.0 (custom)
affected

4.9 (custom)
affected

4.8 (custom)
affected

4.7 (custom)
affected

Credits

Abu Hurayra (Patchstack Bug Bounty Program) finder

John Blackbourn (WordPress core security team lead) coordinator

Timothy Jacobs reporter

Peter Wilson reporter

Mike Nelson reporter

References

patchstack.com/...tive-data-exposure-vulnerability?_s_id=cve vdb-entry

wordpress.org/news/2025/09/wordpress-6-8-3-release/ release-notes

cve.org (CVE-2025-58246)

nvd.nist.gov (CVE-2025-58246)

Download JSON