Sensitive Information Exposure in Simple Comment Editing Plugin for WordPress
CVE-2025-12681
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 November 2025
What is CVE-2025-12681?
The Simple Comment Editing plugin for WordPress is susceptible to a vulnerability that allows unauthenticated users to access sensitive information through the 'ajax_get_comment' function. This exposure can lead to the unauthorized retrieval of user IDs, IP addresses, and email addresses, compromising user privacy and security. All versions up to and including 3.1.0 are affected, necessitating immediate attention from site administrators to mitigate potential data breaches.
Affected Version(s)
Comment Edit Core – Simple Comment Editing * <= 3.1.0