Sensitive Data Exposure in ElasticPress by 10up
CVE-2026-62088

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 September 2026

What is CVE-2026-62088?

The ElasticPress plugin, developed by 10up, contains a vulnerability that enables the insertion of sensitive information into sent data, allowing unauthorized retrieval of embedded sensitive data. This critical issue affects all versions of ElasticPress from its initial release up to 5.3.4, posing significant risks to users by potentially exposing confidential data. It is essential for users to be aware of this vulnerability and update their ElasticPress installations to safeguard against potential data leaks.

Affected Version(s)

ElasticPress <= 5.3.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

murloc.mrglwglwgl | Patchstack Bug Bounty Program
.