CVE-2026-66435: WordPress WP Rollback plugin <= 3.1.2 - Sensitive Data Exposure vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in Devin Walker WP Rollback wp-rollback allows Retrieve Embedded Sensitive Data.This issue affects WP Rollback: from n/a through 3.1.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Rollbackto a version that resolves this vulnerability.Fixed in 3.2.0
Event History
Frequently Asked Questions
Which installations are affected?
WP Rollback versions through 3.1.2 are affected. The available information does not identify a safe fixed version.
Does exploitation require an authenticated WordPress user or user interaction?
No privileges or user interaction are required according to the supplied vector. Exploitation is network-accessible, although the attack complexity is rated high.
What is the potential impact?
Successful exploitation may expose sensitive embedded data. The supplied severity vector indicates high confidentiality impact, with no integrity or availability impact.