Sensitive Data Exposure in 10up Eight Day Week Print Workflow Plugin
CVE-2025-67621

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 December 2025

What is CVE-2025-67621?

The Eight Day Week Print Workflow plugin by 10up has a vulnerability that allows unauthorized retrieval of embedded sensitive information. This exposure can lead to significant privacy breaches as it opens a gateway for malicious actors to access confidential system data. The affected versions range from none specified up to version 1.2.5, making it essential for users of this plugin to evaluate their installations and apply any necessary updates to mitigate risk.

Affected Version(s)

Eight Day Week Print Workflow 0 <= 1.2.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PPzzAArr | Patchstack Bug Bounty Program
.