CVE-2025-58246: medium-severity vulnerability in WordPress
WordPress <= 6.8.2 - (Contributor+) Sensitive Data Exposure Vulnerability
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.3epss 0.3%
exploitation probability
0.3%top 83% of all CVEs
observed exploitation
nono source reports it
Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it.
This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
WordPress · WordPressRelated CVEs — WordPress
In the same product, most dangerous first.
CVE-2026-87902HIGHCVE-2026-87902EPSS 46.1%KEVCVE-2026-63030CRITICALWordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code ExecutionEPSS 10.1%KEVCVE-2026-60137MEDIUMWordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryEPSS 5.9%KEVCVE-2020-11027MEDIUMPassword reset links invalidation issue in WordPressEPSS 13.6%CVE-2023-5561MEDIUMWordPress < 6.3.2 - Unauthenticated Post Author Email DisclosureEPSS 3.9%CVE-2022-3590MEDIUMWP <= 6.1.1 - Unauthenticated Blind SSRF via DNS RebindingEPSS 3.2%