---
id: CVE-2023-39999
title: "Exposure of Sensitive Information to an Unauthorized Actor in WordPress\_from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9…"
summary: "Exposure of Sensitive Information to an Unauthorized Actor in WordPress\_from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9…"
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: wordpress
product: wordpress
affected:
  - 'wordpress >= 4.1, <= 4.1.38'
  - 'wordpress >= 4.2, <= 4.2.35'
  - 'wordpress >= 4.3, <= 4.3.31'
  - 'wordpress >= 4.4, <= 4.4.30'
  - 'wordpress >= 4.5, <= 4.5.29'
  - 'wordpress >= 4.6, <= 4.6.26'
  - 'wordpress >= 4.7, <= 4.7.26'
  - 'wordpress >= 4.8, <= 4.8.22'
  - 'wordpress >= 4.9, <= 4.9.23'
  - 'wordpress >= 5.0, <= 5.0.19'
  - 'wordpress >= 5.1, <= 5.1.16'
  - 'wordpress >= 5.2, <= 5.2.18'
  - 'wordpress >= 5.3, <= 5.3.15'
  - 'wordpress >= 5.4, <= 5.4.13'
  - 'wordpress >= 5.5, <= 5.5.12'
  - 'wordpress >= 5.6, <= 5.6.11'
  - 'wordpress >= 5.7, <= 5.7.9'
  - 'wordpress >= 5.8, <= 5.8.7'
  - 'wordpress >= 5.9, <= 5.9.7'
  - 'wordpress >= 6.0, <= 6.0.5'
  - 'wordpress >= 6.1, <= 6.1.3'
  - 'wordpress >= 6.2, <= 6.2.2'
  - 'wordpress >= 6.3, < 6.3.2'
  - fedora = 37
  - fedora = 38
patched:
  - wordpress 6.3.2
published: '2023-10-13'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T13:16:48.530'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-39999'
references:
  - url: 'https://lists.debian.org/debian-lts-announce/2023/11/msg00014.html'
    label: audit@patchstack.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2EVFT4DPZRFTXJPEPADM22BZVIUD2P66/
    label: audit@patchstack.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCCVDPKOK57WCTH2QJ5DJM3B53RJNZKA/
    label: audit@patchstack.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WQBL4ZQCBFNQ76XHM5257CIBFQRGT5QY/
    label: audit@patchstack.com
  - url: >-
      https://patchstack.com/articles/wordpress-core-6-3-2-security-update-technical-advisory?_s_id=cve
    label: audit@patchstack.com
  - url: >-
      https://patchstack.com/database/vulnerability/wordpress/wordpress-wordpress-core-core-6-3-2-contributor-comment-read-on-private-and-password-protected-post-vulnerability?_s_id=cve
    label: audit@patchstack.com
  - url: 'https://lists.debian.org/debian-lts-announce/2023/11/msg00014.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2EVFT4DPZRFTXJPEPADM22BZVIUD2P66/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCCVDPKOK57WCTH2QJ5DJM3B53RJNZKA/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WQBL4ZQCBFNQ76XHM5257CIBFQRGT5QY/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://patchstack.com/articles/wordpress-core-6-3-2-security-update-technical-advisory?_s_id=cve
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://patchstack.com/database/vulnerability/wordpress/wordpress-wordpress-core-core-6-3-2-contributor-comment-read-on-private-and-password-protected-post-vulnerability?_s_id=cve
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
epss: 0.01045
epssPercentile: 0.62924
ingestedAt: '2026-10-05T13:20:09.429Z'
---

## Overview

Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 through 5.2.18, from 5.1 through 5.1.16, from 5.0 through 5.0.19, from 4.9 through 4.9.23, from 4.8 through 4.8.22, from 4.7 through 4.7.26, from 4.6 through 4.6.26, from 4.5 through 4.5.29, from 4.4 through 4.4.30, from 4.3 through 4.3.31, from 4.2 through 4.2.35, from 4.1 through 4.1.38.

## Affected

- `wordpress >= 4.1, <= 4.1.38`
- `wordpress >= 4.2, <= 4.2.35`
- `wordpress >= 4.3, <= 4.3.31`
- `wordpress >= 4.4, <= 4.4.30`
- `wordpress >= 4.5, <= 4.5.29`
- `wordpress >= 4.6, <= 4.6.26`
- `wordpress >= 4.7, <= 4.7.26`
- `wordpress >= 4.8, <= 4.8.22`
- `wordpress >= 4.9, <= 4.9.23`
- `wordpress >= 5.0, <= 5.0.19`
- `wordpress >= 5.1, <= 5.1.16`
- `wordpress >= 5.2, <= 5.2.18`
- `wordpress >= 5.3, <= 5.3.15`
- `wordpress >= 5.4, <= 5.4.13`
- `wordpress >= 5.5, <= 5.5.12`
- `wordpress >= 5.6, <= 5.6.11`
- `wordpress >= 5.7, <= 5.7.9`
- `wordpress >= 5.8, <= 5.8.7`
- `wordpress >= 5.9, <= 5.9.7`
- `wordpress >= 6.0, <= 6.0.5`
- `wordpress >= 6.1, <= 6.1.3`
- `wordpress >= 6.2, <= 6.2.2`
- `wordpress >= 6.3, < 6.3.2`
- `fedora = 37`
- `fedora = 38`

## Remediation

Upgrade past the affected range:

- `wordpress 6.3.2`
