{"id":"CVE-2025-5760","summary":"Simple History \u003c= 5.8.1 - Authenticated (Administrator+) Sensitive Information Exposure via Detective Mode","details":"The Simple History plugin for WordPress is vulnerable to sensitive data exposure via Detective Mode due to improper sanitization within the append_debug_info_to_context() function in versions prior to 5.8.1. When Detective Mode is enabled, the plugin’s logger captures the entire contents of $_POST (and sometimes raw request bodies or $_GET) without redacting any password‐related keys. As a result, whenever a user submits a login form, whether via native wp_login or a third‐party login widget, their actual password is written in clear text into the logs. An authenticated attacker or any user whose actions generate a login event will have their password recorded; an administrator (or anyone with database read access) can then read those logs and retrieve every captured password.","modified":"2026-08-12T03:51:41.859233052Z","published":"2025-06-06T11:13:16.129Z","database_specific":{"cwe_ids":["CWE-256"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/5xxx/CVE-2025-5760.json","cna_assigner":"Wordfence"},"references":[{"type":"WEB","url":"https://plugins.trac.wordpress.org/changeset/3267487/"},{"type":"WEB","url":"https://simple-history.com/support/detective-mode/"},{"type":"WEB","url":"https://wordpress.org/plugins/simple-history/#developers"},{"type":"WEB","url":"https://wordpress.org/support/topic/security-vulnerability-passwords-stored-as-plain-text-in-logs/"},{"type":"WEB","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b6364415-da02-4236-b635-d8fbd27faa33?source=cve"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/5xxx/CVE-2025-5760.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-5760"},{"type":"REPORT","url":"https://github.com/bonny/WordPress-Simple-History/issues/546"},{"type":"FIX","url":"https://github.com/bonny/WordPress-Simple-History/commit/68eab0cab6882eafef4bfece884093eeda5ac018"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bonny/wordpress-simple-history","events":[{"introduced":"0"},{"fixed":"68eab0cab6882eafef4bfece884093eeda5ac018"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"last_affected":"5.8.1"}]}}],"versions":["5.8.1","5.8.0","5.7.0","5.6.1","5.6.0","5.5.1","5.5.0","5.2.0","5.1.0","5.0.4","5.0.3","5.0.1","5.0.0","4.16.0","4.15.1","4.14.0","4.13.0","4.12.0","4.11.0","4.10.0","4.9.0","4.7.2","4.7.1","4.7.0","4.6.0","4.5.0","4.4.0","4.3.0","4.2.1","4.2.0","4.1.0","4.0.1","4.0.0","3.3.0","3.2.0","3.1.1","3.1.0","3.0.0","2.41.2","2.41.1","2.41.0","2.40.0","2.39.0","2.37.2","2.36","2.33","2.32","2.31.1","2.31","2.30","2.29.2","2.29.1","2.29","2.28.1","2.28","2.25","2.24","2.22","2.21.1","2.21","2.18","2.17","2.16","2.15","2.14.1","2.14","2.13","2.12","2.5.1","2.5","2.4","2.3.1","2.3","2.2.4","2.2.3","2.2.2","2.2.1","2.2","2.1.7","2.1.6","2.1.5","2.1.4","2.1.3","2.1.2","2.1.1","2.1","2.0.30","2.0.29","2.0.28","2.0.27","2.0.26","2.0.25","2.0.24","2.0.23","2.0.22","2.0.21","2.0.20","2.0.19","2.0.18","2.0.17","2.0.15","2.0.14","2.0.13","2.0.12","2.0.11","2.0.10","2.0.9","2.0.8","2.0.7","1.3.11","1.3.10","1.3.9","1.3.8","1.3.7","1.3.6","1.3.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-5760.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"}]}