CVE-2026-66666
WordPress Core <= 7.1.2 - Unauthenticated Sensitive Data Exposure of Comments on Private and Unpublished Posts via Comment Feed vulnerability
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress wordpress allows Retrieve Embedded Sensitive Data.This issue affects WordPress: from n/a through 7.1.2.
| CWE | CWE-201 |
| Vendor | automattic |
| Product | wordpress |
| Ecosystems | |
| Industries | WebMedia |
| Published | Oct 6, 2026 |
| Last Updated | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for automattic wordpress
Be the first to know when new unknown vulnerabilities affecting automattic wordpress are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Automattic / WordPress
7.1 ≤ 7.1.2 7.0 ≤ 7.0.6 6.9 ≤ 6.9.9 6.8 ≤ 6.8.10 6.7 ≤ 6.7.9 6.6 ≤ 6.6.9
References
Credits
Ananda Dhakal (Patchstack)