Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress allows Retrieve Embedded Sensitive Data.
The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it.
This issue affects WordPress: from n/a through 6.8.2
Metrics
Affected Vendors & Products
References
History
Thu, 25 Sep 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Automattic
Automattic wordpress Wordpress Wordpress wordpress |
|
Vendors & Products |
Automattic
Automattic wordpress Wordpress Wordpress wordpress |
Tue, 23 Sep 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 23 Sep 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it. This issue affects WordPress: from n/a through 6.8.2 | |
Title | WordPress core <= 6.8.2 - (Contributor+) Sensitive Data Exposure vulnerability | |
Weaknesses | CWE-201 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-09-23T18:37:38.153Z
Reserved: 2025-08-27T16:19:44.959Z
Link: CVE-2025-58246

Updated: 2025-09-23T18:30:41.999Z

Status : Awaiting Analysis
Published: 2025-09-23T18:15:37.660
Modified: 2025-09-24T18:11:24.520
Link: CVE-2025-58246

No data.