WordPress <= 6.8.2 - (Contributor+) Sensitive Data Exposure Vulnerability
Summary
| CVE | CVE-2025-58246 |
|---|---|
| State | PUBLISHED |
| Assigner | Patchstack |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-09-23 18:15:37 UTC |
| Updated | 2026-04-28 19:34:06 UTC |
| Description | Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it. This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30. |
Risk And Classification
Primary CVSS: v3.1 4.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS: 0.000390000 probability, percentile 0.118490000 (date 2026-04-28)
Problem Types: CWE-201 | CWE-201 CWE-201 Insertion of Sensitive Information Into Sent Data
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | CNA | CVSS | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | WordPress | WordPress | affected 6.8 6.8.2 custom | Not specified |
| CNA | WordPress | WordPress | affected 6.7 6.7.3 custom | Not specified |
| CNA | WordPress | WordPress | affected 6.6 6.6.3 custom | Not specified |
| CNA | WordPress | WordPress | affected 6.5 6.5.6 custom | Not specified |
| CNA | WordPress | WordPress | affected 6.4 6.4.6 custom | Not specified |
| CNA | WordPress | WordPress | affected 6.3 6.3.6 custom | Not specified |
| CNA | WordPress | WordPress | affected 6.2 6.2.7 custom | Not specified |
| CNA | WordPress | WordPress | affected 6.1 6.1.8 custom | Not specified |
| CNA | WordPress | WordPress | affected 6.0 6.0.10 custom | Not specified |
| CNA | WordPress | WordPress | affected 5.9 5.9.11 custom | Not specified |
| CNA | WordPress | WordPress | affected 5.8 5.8.11 custom | Not specified |
| CNA | WordPress | WordPress | affected 5.7 5.7.13 custom | Not specified |
| CNA | WordPress | WordPress | affected 5.6 5.6.15 custom | Not specified |
| CNA | WordPress | WordPress | affected 5.5 5.5.16 custom | Not specified |
| CNA | WordPress | WordPress | affected 5.4 5.4.17 custom | Not specified |
| CNA | WordPress | WordPress | affected 5.3 5.3.19 custom | Not specified |
| CNA | WordPress | WordPress | affected 5.2 5.2.22 custom | Not specified |
| CNA | WordPress | WordPress | affected 5.1 5.1.20 custom | Not specified |
| CNA | WordPress | WordPress | affected 5.0 5.0.23 custom | Not specified |
| CNA | WordPress | WordPress | affected 4.9 4.9.27 custom | Not specified |
| CNA | WordPress | WordPress | affected 4.8 4.8.26 custom | Not specified |
| CNA | WordPress | WordPress | affected 4.7 4.7.30 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wordpress.org/news/2025/09/wordpress-6-8-3-release | [email protected] | wordpress.org | |
| patchstack.com/database/wordpress/wordpress/wordpress/vulnerability/wordpres... | [email protected] | patchstack.com | |
| https://patchstack.com/database/wordpress/wordpress/wordpress/vulnerability/wordpress-wordpress-wordpress-6-8-2-sensitive-data-exposure-vulnerability?_s_id=cve | MITRE | patchstack.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Abu Hurayra (Patchstack Bug Bounty Program) (en)
CNA: John Blackbourn (WordPress core security team lead) (en)
CNA: Timothy Jacobs (en)
CNA: Peter Wilson (en)
CNA: Mike Nelson (en)
Additional Advisory Data
Solutions
CNA: Update WordPress to one of the following patched or higher versions: 6.8.3, 6.7.4, 6.6.4, 6.5.7, 6.4.7, 6.3.7, 6.2.8, 6.1.9, 6.0.11, 5.9.12, 5.8.12, 5.7.14, 5.6.16, 5.5.17, 5.4.18, 5.3.20, 5.2.23, 5.1.21, 5.0.24, 4.9.28, 4.8.27, or 4.7.31.
There are currently no legacy QID mappings associated with this CVE.