CVE-2025-58246
Last modified
CVE-2025-58246 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to exploit it. This issue affects WordPress: from 6.8 through 6.8.2, from 6.7 through 6.7.3, from 6.6 through 6.6.3, from 6.5 through 6.5.6, from 6.4 through 6.4.6, from 6.3 through 6.3.6, from 6.2 through 6.2.7, from 6.1 through 6.1.8, from 6.0 through 6.0.10, from 5.9 through 5.9.11, from 5.8 through 5.8.11, from 5.7 through 5.7.13, from 5.6 through 5.6.15, from 5.5 through 5.5.16, from 5.4 through 5.4.17, from 5.3 through 5.3.19, from 5.2 through 5.2.22, from 5.1 through 5.1.20, from 5.0 through 5.0.23, from 4.9 through 4.9.27, from 4.8 through 4.8.26, from 4.7 through 4.7.30.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-58246?
How severe is CVE-2025-58246?
How do I fix CVE-2025-58246?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-58240Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-58241Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-58242Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-58243Missing Authorization vulnerability in Jthemes imEvent imeve…5.3
- CVE-2025-58244Cross-Site Request Forgery (CSRF) vulnerability in Anps Cons…8.8
- CVE-2025-58245Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-58247Missing Authorization vulnerability in templateinvaders TI W…5.3
- CVE-2025-58248Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-58249Insertion of Sensitive Information Into Sent Data vulnerabil…4.3
- CVE-2025-5825Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade R…7.5
- CVE-2025-58250Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme…8.8
- CVE-2025-58251Missing Authorization vulnerability in POSIMYTH Sticky Heade…4.3
Are you affected by CVE-2025-58246?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
