🔐 CVE Alert

CVE-2026-66666

UNKNOWN 0.0

WordPress Core <= 7.1.2 - Unauthenticated Sensitive Data Exposure of Comments on Private and Unpublished Posts via Comment Feed vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress wordpress allows Retrieve Embedded Sensitive Data.This issue affects WordPress: from n/a through 7.1.2.

CWE CWE-201
Vendor automattic
Product wordpress
Ecosystems
Industries
WebMedia
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for automattic wordpress

Be the first to know when new unknown vulnerabilities affecting automattic wordpress are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Automattic / WordPress
7.1 ≤ 7.1.2 7.0 ≤ 7.0.6 6.9 ≤ 6.9.9 6.8 ≤ 6.8.10 6.7 ≤ 6.7.9 6.6 ≤ 6.6.9

References

NVD ↗ CVE.org ↗ EPSS Data ↗
patchstack.com: https://patchstack.com/database/wordpress/wordpress/wordpress/vulnerability/wordpress-wordpress-wordpress-7-1-2-sensitive-data-exposure-vulnerability?_s_id=cve

Credits

Ananda Dhakal (Patchstack)