{"id":"CVE-2025-58246","summary":"WordPress \u003c= 6.8.2 - (Contributor+) Sensitive Data Exposure Vulnerability","details":"Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it.\nThis issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30.","aliases":["BIT-wordpress-2025-58246","BIT-wordpress-multisite-2025-58246"],"modified":"2026-07-15T01:49:13.930202324Z","published":"2025-09-23T17:17:12.399Z","related":["CGA-6f73-4c2q-p7mx"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58246.json","cna_assigner":"Patchstack","cwe_ids":["CWE-201"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58246.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58246"},{"type":"ADVISORY","url":"https://patchstack.com/database/wordpress/wordpress/wordpress/vulnerability/wordpress-wordpress-wordpress-6-8-2-sensitive-data-exposure-vulnerability?_s_id=cve"},{"type":"ADVISORY","url":"https://wordpress.org/news/2025/09/wordpress-6-8-3-release/"},{"type":"PACKAGE","url":"https://github.com/WordPress/WordPress"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wordpress/wordpress","events":[{"introduced":"6ba3d560fc2b033654f6dbfc6093fefb5c50f148"},{"last_affected":"7a06b8b559b6979e66c3d52307c29fc036d262b4"},{"introduced":"7766f0a793653329067bd50874872cc363af4461"},{"last_affected":"384b59829b3ba84a6ab583dfdc99f94780bbc416"},{"introduced":"b9bdf794320b132e6a4ce1538e988e6d31be33b0"},{"last_affected":"478c0c09ad61893118569120f8bcbcbc7b56a71b"},{"introduced":"e75a577410e912e1408c49ace9103c3ee9997d76"},{"last_affected":"5d0e7828d261b0c63663871f78a325e73eac83f4"},{"introduced":"e2d61d78ede843c2d05f44a4e15f30a57fb47d95"},{"last_affected":"d87719a295aac95558616cd32bf9effb89c5414b"},{"introduced":"ac3899153a790a6f060dc816ff94812e0fd99875"},{"last_affected":"502ec1d5972dd1785162ea5d50d0f7da5fb3c1de"},{"introduced":"17e2eff4aa3beb2802cbec12b6f08e2fbf69893d"},{"last_affected":"5666a268faa3ec81f10e0e9b37d44cd77ca9ecf4"},{"introduced":"6c5d5b5dcb9712bfc400b09cb6627e42898527af"},{"last_affected":"9daf160311b8b4d204b6d46179b8caa3d2c1b74f"},{"introduced":"cc101b64012b16d087780657a2b828ccd7794a63"},{"last_affected":"9aab5018ed5df11af93d24997cfef9642bf5ede4"},{"introduced":"73157386d069425c5e6ea7c4fc0122e8a9b58a7b"},{"last_affected":"00d51db8c3e324f3b7654f0a2a2e2caf62d37b78"},{"introduced":"50caeb6e61ad0c49d2c7e1d6d5115047a011f590"},{"last_affected":"7170f2663abe89af929b7a4c4b82d2fb5925fd3e"},{"introduced":"058f9903676a7efaee534a682df0a2a8b87574d8"},{"last_affected":"27ea70c8dea6adc958946027da0f144cc250d87e"},{"introduced":"965fcddcf68cf4fd122ae24b992e242dfea1d773"},{"last_affected":"b9126fed8f38f35b104e9c5855318ace4f967c9f"},{"introduced":"537fd931bc02e6e934a2d774422b897871aa87ad"},{"last_affected":"106aec8559310134e9c37b9e68175154a012cf8c"},{"introduced":"9ff4499281663b0c772787fd4a60538288f842e9"},{"last_affected":"dd1a5130e4400aa573355fb3176a4822602cf766"},{"introduced":"50dc0ca5bb332c895f0f39fe4e6ee1e4a43e06dc"},{"last_affected":"73a72bc77a57a647e3a8d12254994eb05762337c"},{"introduced":"6fe64752be3260f2a47f38e68c2cb77400e5a0c9"},{"last_affected":"acb0482db358a62bad2c16a98308227827e2e8d9"},{"introduced":"c33464a4554cff8a082bc353d9226d8104b80d2b"},{"last_affected":"b77f53c0715a6d4023c5b59d62f4d6bf9a9d9b6c"},{"introduced":"491c67be12ca8a9fe37ae38307ba7e298c976ec3"},{"last_affected":"3ff6298e226db543d514ef200acb119570331e5e"},{"introduced":"29ffbff370968ae48a1b7a34e35c8b8e75cf0f91"},{"last_affected":"d4d46ed1c5d2cdb88db38a8798d480326e41e209"},{"introduced":"06fa4161aa74619239cf27017d124081c825684a"},{"last_affected":"dff45f073498c3b261bd1c871f88833e7746a4d2"},{"introduced":"14247ee4302378d292863865c643abe99bbfe3c7"},{"last_affected":"f9331fae6003a405847f360d533a07f99f5768ca"}],"database_specific":{"extracted_events":[{"introduced":"6.8"},{"last_affected":"6.8.2"},{"introduced":"6.7"},{"last_affected":"6.7.3"},{"introduced":"6.6"},{"last_affected":"6.6.3"},{"introduced":"6.5"},{"last_affected":"6.5.6"},{"introduced":"6.4"},{"last_affected":"6.4.6"},{"introduced":"6.3"},{"last_affected":"6.3.6"},{"introduced":"6.2"},{"last_affected":"6.2.7"},{"introduced":"6.1"},{"last_affected":"6.1.8"},{"introduced":"6.0"},{"last_affected":"6.0.10"},{"introduced":"5.9"},{"last_affected":"5.9.11"},{"introduced":"5.8"},{"last_affected":"5.8.11"},{"introduced":"5.7"},{"last_affected":"5.7.13"},{"introduced":"5.6"},{"last_affected":"5.6.15"},{"introduced":"5.5"},{"last_affected":"5.5.16"},{"introduced":"5.4"},{"last_affected":"5.4.17"},{"introduced":"5.3"},{"last_affected":"5.3.19"},{"introduced":"5.2"},{"last_affected":"5.2.22"},{"introduced":"5.1"},{"last_affected":"5.1.20"},{"introduced":"5.0"},{"last_affected":"5.0.23"},{"introduced":"4.9"},{"last_affected":"4.9.27"},{"introduced":"4.8"},{"last_affected":"4.8.26"},{"introduced":"4.7"},{"last_affected":"4.7.30"}],"source":"AFFECTED_FIELD"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-58246.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}