CVE-2025-58246: WordPress <= 6.8.2 - (Contributor+) Sensitive Data Exposure Vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it. This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30.
Other sources
Insertion of Sensitive Information Into Sent Data vulnerability in WordPress WordPress wordpress allows Retrieve Embedded Sensitive Data.This issue affects WordPress: from n/a through <= 6.8.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58246?
CVE-2025-58246 is classified as a low-severity vulnerability.
How do I fix CVE-2025-58246?
To fix CVE-2025-58246, update your Automattic WordPress installation to the latest version that addresses this vulnerability.
What type of data is exposed in CVE-2025-58246?
CVE-2025-58246 allows for the retrieval of embedded sensitive data within the sent data.
Who is affected by CVE-2025-58246?
CVE-2025-58246 affects all Automattic WordPress versions up to and including 6.8.2.
Is there a patch available for CVE-2025-58246?
Yes, the WordPress Core security team is actively working on a patch to fix CVE-2025-58246.