{"id":"BIT-wordpress-2025-41240","details":"The Bitnami WordPress Helm chart mounts Kubernetes Secrets under a predictable path (/opt/bitnami/wordpress/secrets) that is located within the web server document root. In affected versions, this can lead to unauthenticated access to sensitive credentials via HTTP/S. A remote attacker could retrieve these secrets by accessing specific URLs if the application is exposed externally. The issue affects deployments using the default value of usePasswordFiles=true, which mounts secrets as files into the container filesystem.","aliases":["BIT-appsmith-2025-41240","BIT-drupal-2025-41240","CVE-2025-41240","GHSA-wgg9-9qgw-529w"],"modified":"2026-07-08T07:10:18.014975407Z","published":"2025-07-23T14:00:00Z","database_specific":{"cpes":["cpe:2.3:*:wordpress:wordpress:*:*:*:*:*:*:*:*"],"severity":"Critical"},"references":[{"type":"WEB","url":"https://github.com/bitnami/charts/security/advisories/GHSA-wgg9-9qgw-529w"}],"affected":[{"package":{"name":"wordpress","ecosystem":"Bitnami","purl":"pkg:bitnami/wordpress"},"ranges":[{"type":"SEMVER","events":[{"introduced":"6.7.2-7"},{"fixed":"6.8.2-1"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/wordpress/BIT-wordpress-2025-41240.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/RL:O"}]}],"schema_version":"1.7.5"}