Sensitive Information Exposure in WP Rollback Plugin by WordPress
CVE-2026-66435

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-66435?

The WP Rollback plugin by WordPress is susceptible to a vulnerability that allows attackers to retrieve embedded sensitive data. This issue affects users of WP Rollback up to version 3.1.2, potentially compromising the confidentiality of sensitive information during data transmission. It is crucial for users to ensure they are using a secure version of the plugin to mitigate this risk and protect their data.

Affected Version(s)

WP Rollback 0 <= 3.1.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.