Sensitive Data Exposure in ElasticPress by 10up
CVE-2026-62088
5.3MEDIUM
What is CVE-2026-62088?
The ElasticPress plugin, developed by 10up, contains a vulnerability that enables the insertion of sensitive information into sent data, allowing unauthorized retrieval of embedded sensitive data. This critical issue affects all versions of ElasticPress from its initial release up to 5.3.4, posing significant risks to users by potentially exposing confidential data. It is essential for users to be aware of this vulnerability and update their ElasticPress installations to safeguard against potential data leaks.
Affected Version(s)
ElasticPress <= 5.3.4