CVE-2025-6593: "{{SITENAME}} registered email address has been changed" email sent to unverified email addresses
Published Feb 2, 2026
·Updated
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/user/User.Php.
This issue affects MediaWiki: from 1.27.0 before 1.39.13, 1.42.7 1.43.2, 1.44.0.
Affected Software
1 affected component
Wikimedia Foundation MediaWiki>=1.27.0<1.39.13
Event History
Feb 2, 2026
CVE Published
via MITRE·11:01 PM
Data Sourced
via MITRE·11:01 PM
Description
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-6593?
CVE-2025-6593 is considered a medium severity vulnerability that allows unverified email addresses to receive change notifications.
2
How do I fix CVE-2025-6593?
To fix CVE-2025-6593, upgrade your MediaWiki installation to version 1.39.13 or later.
3
What versions of MediaWiki are affected by CVE-2025-6593?
CVE-2025-6593 affects MediaWiki versions from 1.27.0 up to but not including 1.39.13.
4
What impact does CVE-2025-6593 have on user privacy?
CVE-2025-6593 can potentially compromise user privacy by sending sensitive account update emails to unverified addresses.
5
Is there a workaround for CVE-2025-6593 if an upgrade cannot be performed?
Currently, there is no documented workaround for CVE-2025-6593, and the recommended action is to upgrade MediaWiki.