Remote Title Disclosure Vulnerability in WordPress Products
CVE-2025-54352

3.7LOW

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-54352?

WordPress versions 3.5 to 6.8.2 are susceptible to a vulnerability that allows remote attackers to infer the titles of private and draft posts through XML-RPC pingback.ping requests. This poses a significant risk to the confidentiality of unpublished content, making it easy for attackers to exploit this oversight. Despite the security implications, the vendor has indicated that they will not be changing this behavior.

Affected Version(s)

WordPress 3.5 <= 6.8.2

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54352 : Remote Title Disclosure Vulnerability in WordPress Products