The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 via the 'context_blog_modal_popup' due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Postmagthemes
Postmagthemes context Blog Wordpress Wordpress wordpress |
|
| Vendors & Products |
Postmagthemes
Postmagthemes context Blog Wordpress Wordpress wordpress |
Wed, 18 Feb 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 via the 'context_blog_modal_popup' due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to. | |
| Title | Context Blog <= 1.2.5 - Unauthenticated Private Post Disclosure | |
| Weaknesses | CWE-200 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-02-18T12:53:56.485Z
Reserved: 2025-10-22T14:12:09.205Z
Link: CVE-2025-12074
Updated: 2026-02-18T12:26:34.735Z
Status : Awaiting Analysis
Published: 2026-02-18T05:16:16.950
Modified: 2026-02-18T17:51:53.510
Link: CVE-2025-12074
No data.