CVE-2025-54352: Low severity WordPress WordPress vulnerability
Published Jul 21, 2025
·Updated
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.
Affected Software
1 affected component
WordPress WordPress>=3.5<=6.8.2
Event History
Jul 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-54352?
CVE-2025-54352 is classified as a medium severity vulnerability due to the potential exposure of private and draft post titles.
2
How do I fix CVE-2025-54352?
To address CVE-2025-54352, consider disabling XML-RPC or using security plugins that limit pingback functionality.
3
What versions of WordPress are affected by CVE-2025-54352?
CVE-2025-54352 affects WordPress versions from 3.5 to 6.8.2.
4
What risks does CVE-2025-54352 pose to my WordPress site?
CVE-2025-54352 allows attackers to guess the titles of private and draft posts, potentially leading to privacy breaches.
5
Is there an official fix for CVE-2025-54352 from WordPress?
As of now, the supplier of WordPress has not provided an official fix or change in response to CVE-2025-54352.