Sensitive Information Exposure in Shelf Planner Plugin for WordPress
CVE-2025-11891

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 November 2025

What is CVE-2025-11891?

The Shelf Planner plugin for WordPress has a vulnerability that exposes sensitive information through publicly accessible log files. This issue allows unauthenticated attackers to retrieve potentially critical data stored in these files, posing a significant risk to website security. Users of the plugin are highly encouraged to update to the latest version to mitigate this risk and protect their sensitive information.

Affected Version(s)

Shelf Planner * <= 2.7.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas Benjamin Friedli
.