← Back to CVE List
CVE-2026-66666NVD
Vulnerability Summary
Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress allows Retrieve Embedded Sensitive Data.
This issue affects WordPress: from 7.1 through 7.1.2, from 7.0 through 7.0.6, from 6.9 through 6.9.9, from 6.8 through 6.8.10, from 6.7 through 6.7.9, and from 6.6 through 6.6.9.
This issue affects WordPress: from 7.1 through 7.1.2, from 7.0 through 7.0.6, from 6.9 through 6.9.9, from 6.8 through 6.8.10, from 6.7 through 6.7.9, and from 6.6 through 6.6.9.
CVSS v4.0 Base Metrics — Score 6.9 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)None
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- Automattic WordPress >= 7.1 and <= 7.1.2
- Automattic WordPress >= 7.0 and <= 7.0.6
- Automattic WordPress >= 6.9 and <= 6.9.9
- Automattic WordPress >= 6.8 and <= 6.8.10
- Automattic WordPress >= 6.7 and <= 6.7.9
- Automattic WordPress >= 6.6 and <= 6.6.9
- Automattic WordPress 7.1.2
- Automattic WordPress 7.0.6
- Automattic WordPress 6.9.9
- Automattic WordPress 6.8.10
- Automattic WordPress 6.7.9
- Automattic WordPress 6.6.9
External References
- https://patchstack.com/database/wordpress/wordpress/wordpress/vulnerability/wordpress-wordpress-wordpress-7-1-2-sensitive-data-exposure-vulnerability?_s_id=cve
- https://wordpress.org/news/2026/10/wordpress-7-1-3-maintenance-and-security-release/
- https://patchstack.com/articles/wordpress-7-1-3-security-release?_s_id=cve