CVE-2025-67931: WordPress BulletProof Security plugin <= 6.9 - Sensitive Data Exposure vulnerability
Published Jan 8, 2026
·Updated
Insertion of Sensitive Information Into Sent Data vulnerability in AITpro BulletProof Security bulletproof-security allows Retrieve Embedded Sensitive Data.This issue affects BulletProof Security: from n/a through <= 6.9.
Affected Software
1 affected component
wordpress/bulletproof-security<=6.9
Event History
Jan 8, 2026
CVE Published
via MITRE·09:17 AM
Data Sourced
via MITRE·09:17 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-67931?
CVE-2025-67931 is classified as a high-severity vulnerability due to its potential for sensitive data exposure.
2
How do I fix CVE-2025-67931?
To fix CVE-2025-67931, update the BulletProof Security plugin to the latest version beyond 6.9.
3
What types of sensitive information are exposed by CVE-2025-67931?
CVE-2025-67931 can expose embedded sensitive data that may include personal user information.
4
Which versions of BulletProof Security are affected by CVE-2025-67931?
CVE-2025-67931 affects BulletProof Security versions up to and including 6.9.
5
Is CVE-2025-67931 a remote attack vector?
CVE-2025-67931 can potentially be exploited remotely if the vulnerable version is exposed to untrusted users.