CVE-2026-66666: medium-severity vulnerability in Automattic WordPress
WordPress Core <= 7.1.2 - Unauthenticated Sensitive Data Exposure of Comments on Private and Unpublished Posts via Comment Feed vulnerability
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.9epss 0.3%
exploitation probability
0.3%top 80% of all CVEs
observed exploitation
nono source reports it
Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress allows Retrieve Embedded Sensitive Data.
This issue affects WordPress: from 7.1 through 7.1.2, from 7.0 through 7.0.6, from 6.9 through 6.9.9, from 6.8 through 6.8.10, from 6.7 through 6.7.9, and from 6.6 through 6.6.9.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Automattic · WordPressRelated CVEs — Automattic WordPress
In the same product, most dangerous first.
CVE-2024-32111MEDIUMWordPress core < 6.5.5 - Auth. Arbitrary .html File Read (Windows Only) vulnerabilityEPSS 0.5%CVE-2026-93485HIGHWordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2024-31111MEDIUMWordPress Core < 6.5.5 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%
References
https://patchstack.com/articles/wordpress-7-1-3-security-release?_s_id=cvehttps://patchstack.com/database/wordpress/wordpress/wordpress/vulnerability/wordpress-wordpress-wordpress-7-1-2-sensitive-data-exposure-vulnerability?_s_id=cvehttps://wordpress.org/news/2026/10/wordpress-7-1-3-maintenance-and-security-release/