CVE-2025-58246

WordPress <= 6.8.2 - (Contributor+) Sensitive Data Exposure Vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it. This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30.


We have discovered 7,827,111 live websites that are affected by CVE-2025-58246.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains7,827,111 live websites (100% of WordPress install base)
Vulnerable Versions
  • from 4.7 through 4.7.30
  • from 4.8 through 4.8.26
  • from 4.9 through 4.9.27
  • from 5 through 5.0.23
  • from 5.1 through 5.1.20
  • from 5.2 through 5.2.22
  • from 5.3 through 5.3.19
  • from 5.4 through 5.4.17
  • from 5.5 through 5.5.16
  • from 5.6 through 5.6.15
  • from 5.7 through 5.7.13
  • from 5.8 through 5.8.11
  • from 5.9 through 5.9.11
  • from 6 through 6.0.10
  • from 6.1 through 6.1.8
  • from 6.2 through 6.2.7
  • from 6.3 through 6.3.6
  • from 6.4 through 6.4.6
  • from 6.5 through 6.5.6
  • from 6.6 through 6.6.3
  • from 6.7 through 6.7.3
  • from 6.8 through 6.8.2
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-201 Insertion of Sensitive Information Into Sent Data



Details

  • Published - Sep 23, 2025
  • Updated - Oct 1, 2025

Credits

  • Abu Hurayra (Patchstack Bug Bounty Program) (finder)
  • John Blackbourn (WordPress core security team lead) (coordinator)
  • Timothy Jacobs (reporter)
  • Peter Wilson (reporter)
  • Mike Nelson (reporter)

Website Distribution by Country

Number of websites using CVE-2025-58246
United States2,642,004 websites



Germany748,456 websites
Japan464,385 websites
GB343,683 websites
France326,805 websites
Italy262,372 websites
Netherlands239,104 websites
Russia195,515 websites
Poland185,563 websites
Canada184,879 websites

Website Distribution by TLD

Number of websites using CVE-2025-58246
.com3,529,590 websites
.de454,365 websites
.org395,021 websites
.net238,092 websites
.nl207,842 websites
.co.uk198,659 websites
.it179,239 websites
.ru163,340 websites
.com.br142,365 websites
.pl139,613 websites

Websites affected by CVE-2025-58246

Top websites that are affected by CVE-2025-58246. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**
********.*********.com United States**
***************.org United States***
******.net United States***
**********.com United States***
**********.com United States***
*******.com United States***
*****.net Singapore***
****.*****.com United States***
****.******.com Singapore***
See full domain list

FAQ

CVE-2025-58246 is Insertion of Sensitive Information Into Sent Data in WordPress
A total of 7,827,111 websites have been identified as vulnerable to CVE-2025-58246, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2025-58246 vulnerability.
WordPress versions up to and including 6.8.2 are vulnerable to CVE-2025-58246.