CVE-2025-68606

WordPress PostX plugin <= 5.0.3 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPXPO PostX ultimate-post allows Retrieve Embedded Sensitive Data.This issue affects PostX: from n/a through <= 5.0.3.


We have discovered 5,393 live websites that are affected by CVE-2025-68606.

Run a Free Instant Scan




Affected Software

Product  Ultimate Post
Category Wordpress Plugins
Vulnerable Domains5,393 live websites (85% of Ultimate Post install base)
Vulnerable Versions
  • from 0 through 5.0.3
Vulnerable Versions Count127 versions ( 98% of all versions)



Details

  • Published - Dec 24, 2025
  • Updated - Jan 20, 2026

Credits

  • Doan Dinh Van | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2025-68606
United States2,386 websites



Poland461 websites
Germany411 websites
France250 websites
GB168 websites
Cyprus139 websites
Spain138 websites
Italy120 websites
Netherlands97 websites
Japan84 websites

Website Distribution by TLD

Number of websites using CVE-2025-68606
.com2,577 websites
.pl396 websites
.org332 websites
.de207 websites
.net200 websites
.it104 websites
.fr103 websites
.co.uk96 websites
.nl93 websites
.jp77 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-68606

Top websites that are affected by CVE-2025-68606. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States*,***
*********************.com United States**,***
*****.ca Canada**,***
***********.net United States**,***
*******.****.edu United States***,***
***.***.br Brazil***,***
***************************.de Germany***,***
************.com United States***,***
***************.com United States***,***
**************.com Cyprus***,***
See full domain list

FAQ

A total of 5,393 websites have been identified as vulnerable to CVE-2025-68606, based on global website indexing conducted by WebTechSurvey.
The Ultimate Post is affected by the CVE-2025-68606 vulnerability.
Ultimate Post versions up to and including 5.0.3 are vulnerable to CVE-2025-68606.