CVE-2025-39556: WordPress Mediavine Control Panel plugin <= 2.10.6 - Sensitive Data Exposure vulnerability
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mediavine Mediavine Control Panel allows Retrieve Embedded Sensitive Data. This issue affects Mediavine Control Panel: from n/a through 2.10.6.
Other sources
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mediavine Mediavine Control Panel mediavine-control-panel allows Retrieve Embedded Sensitive Data.This issue affects Mediavine Control Panel: from n/a through <= 2.10.6.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39556?
CVE-2025-39556 is classified as a medium-severity vulnerability due to its potential to expose sensitive system information.
How do I fix CVE-2025-39556?
To fix CVE-2025-39556, update the Mediavine Control Panel to version 2.10.7 or later.
What versions of Mediavine Control Panel are affected by CVE-2025-39556?
CVE-2025-39556 affects Mediavine Control Panel versions from n/a up to 2.10.6.
What kind of information is exposed by CVE-2025-39556?
CVE-2025-39556 allows unauthorized access to retrieve embedded sensitive data within the Mediavine Control Panel.
Is there a risk of data breach associated with CVE-2025-39556?
Yes, CVE-2025-39556 poses a risk of data breach by allowing unauthorized individuals to access sensitive system information.