Sensitive Information Exposure in Simple Comment Editing Plugin for WordPress
CVE-2025-12681

5.3MEDIUM

What is CVE-2025-12681?

The Simple Comment Editing plugin for WordPress is susceptible to a vulnerability that allows unauthenticated users to access sensitive information through the 'ajax_get_comment' function. This exposure can lead to the unauthorized retrieval of user IDs, IP addresses, and email addresses, compromising user privacy and security. All versions up to and including 3.1.0 are affected, necessitating immediate attention from site administrators to mitigate potential data breaches.

Affected Version(s)

Comment Edit Core – Simple Comment Editing * <= 3.1.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Powpy
.
CVE-2025-12681 : Sensitive Information Exposure in Simple Comment Editing Plugin for WordPress