First published: Sun Sep 13 2020(Updated: )
In wp-includes/comment-template.php in WordPress before 5.4.2, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress WordPress | <5.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25286 is a vulnerability in WordPress before version 5.4.2 that allows sometimes allows comments from a post or page to be seen in the latest comments even if the post or page was not public.
CVE-2020-25286 has a severity rating of medium with a severity value of 5.3.
WordPress versions up to and excluding 5.4.2 are affected by CVE-2020-25286.
To fix CVE-2020-25286, it is recommended to update WordPress to version 5.4.2 or later.
You can find more information about CVE-2020-25286 on the WordPress official website and the security changeset page.