CVE-2025-58246

WordPress <= 6.8.2 - (Contributor+) Sensitive Data Exposure Vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it. This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30.


We have discovered 995,594 live websites that are affected by CVE-2025-58246.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains995,594 live websites (12% of WordPress install base)
Vulnerable Versions
  • from 4.7 through 4.7.30
  • from 4.8 through 4.8.26
  • from 4.9 through 4.9.27
  • from 5 through 5.0.23
  • from 5.1 through 5.1.20
  • from 5.2 through 5.2.22
  • from 5.3 through 5.3.19
  • from 5.4 through 5.4.17
  • from 5.5 through 5.5.16
  • from 5.6 through 5.6.15
  • from 5.7 through 5.7.13
  • from 5.8 through 5.8.11
  • from 5.9 through 5.9.11
  • from 6 through 6.0.10
  • from 6.1 through 6.1.8
  • from 6.2 through 6.2.7
  • from 6.3 through 6.3.6
  • from 6.4 through 6.4.6
  • from 6.5 through 6.5.6
  • from 6.6 through 6.6.3
  • from 6.7 through 6.7.3
  • from 6.8 through 6.8.2
Vulnerable Versions Count323 versions ( 22% of all versions)


Common Weakness Enumeration

CWE-201 Insertion of Sensitive Information Into Sent Data



Details

  • Published - Sep 23, 2025
  • Updated - Apr 28, 2026

Credits

  • Abu Hurayra (Patchstack Bug Bounty Program) (finder)
  • John Blackbourn (WordPress core security team lead) (coordinator)
  • Timothy Jacobs (reporter)
  • Peter Wilson (reporter)
  • Mike Nelson (reporter)

Website Distribution by Country

Number of websites using CVE-2025-58246
United States266,120 websites



Japan96,976 websites
Germany80,472 websites
Italy47,679 websites
Russia41,973 websites
GB40,838 websites
Poland37,338 websites
France33,030 websites
Netherlands27,228 websites
Spain23,241 websites

Website Distribution by TLD

Number of websites using CVE-2025-58246
.com407,546 websites
.de46,455 websites
.org43,869 websites
.ru36,373 websites
.net32,124 websites
.it32,041 websites
.pl28,560 websites
.nl23,511 websites
.co.uk22,408 websites
.jp22,138 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-58246

Top websites that are affected by CVE-2025-58246. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.net Canada***
****.******.com Singapore***
*********.space United States***
********.info United States***
***************.org United States***
******.com United States***
****.*****.net United States***
**********.com United States***
******.*******.org United States***
*********.net United States***
See full domain list

FAQ

CVE-2025-58246 is Insertion of Sensitive Information Into Sent Data in WordPress
A total of 995,594 websites have been identified as vulnerable to CVE-2025-58246, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2025-58246 vulnerability.
WordPress versions up to and including 6.8.2 are vulnerable to CVE-2025-58246.