Sensitive Data Exposure in WordPress by Automattic
CVE-2026-66666

6.9MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-66666?

The vulnerability in Automattic's WordPress allows for the unintended retrieval of embedded sensitive data. This issue can compromise users' privacy and security, affecting versions of WordPress from n/a through 7.1.2. It is essential for users to apply updates and security measures to safeguard against unauthorized access to sensitive information.

Affected Version(s)

WordPress 7.1 <= 7.1.2

WordPress 7.0 <= 7.0.6

WordPress 6.9 <= 6.9.9

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.