Remote Title Disclosure Vulnerability in WordPress Products
CVE-2025-54352
3.7LOW
What is CVE-2025-54352?
WordPress versions 3.5 to 6.8.2 are susceptible to a vulnerability that allows remote attackers to infer the titles of private and draft posts through XML-RPC pingback.ping requests. This poses a significant risk to the confidentiality of unpublished content, making it easy for attackers to exploit this oversight. Despite the security implications, the vendor has indicated that they will not be changing this behavior.
Affected Version(s)
WordPress 3.5 <= 6.8.2