CVE-2023-39999Medium· 4.3▾ SunlitExposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.0%
Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38.
wordpress >= 4.1, <= 4.1.38wordpress >= 4.2, <= 4.2.35wordpress >= 4.3, <= 4.3.31wordpress >= 4.4, <= 4.4.30wordpress >= 4.5, <= 4.5.29wordpress >= 4.6, <= 4.6.26wordpress >= 4.7, <= 4.7.26wordpress >= 4.8, <= 4.8.22wordpress >= 4.9, <= 4.9.23wordpress >= 5.0, <= 5.0.19wordpress >= 5.1, <= 5.1.16wordpress >= 5.2, <= 5.2.18wordpress >= 5.3, <= 5.3.15wordpress >= 5.4, <= 5.4.13wordpress >= 5.5, <= 5.5.12wordpress >= 5.6, <= 5.6.11wordpress >= 5.7, <= 5.7.9wordpress >= 5.8, <= 5.8.7wordpress >= 5.9, <= 5.9.7wordpress >= 6.0, <= 6.0.5wordpress >= 6.1, <= 6.1.3wordpress >= 6.2, <= 6.2.2wordpress >= 6.3, < 6.3.2fedora = 37fedora = 38Upgrade past the affected range:
wordpress 6.3.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-87902High· 8.1An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories
CVE-2026-93485High· 7.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 throug…
CVE-2022-31746Medium· 6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header
CVE-2026-105302Medium· 5.7A flaw was found in the User Session Note mapper of the Keycloak identity and access management solution
CVE-2026-105211High· 8.1ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type
CVE-2026-105205Medium· 5.3SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block IDs and reference counts from password-protected and publish-disabled documents by querying a published documen…