CVE-2026-66666

Summary

Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress allows Retrieve Embedded Sensitive Data.

This issue affects WordPress: from 7.1 through 7.1.2, from 7.0 through 7.0.6, from 6.9 through 6.9.9, from 6.8 through 6.8.10, from 6.7 through 6.7.9, and from 6.6 through 6.6.9.

Affected Software

VendorProductVersion RangeStatus
AutomatticWordPress7.1 <= 7.1.2affected
AutomatticWordPress7.0 <= 7.0.6affected
AutomatticWordPress6.9 <= 6.9.9affected
AutomatticWordPress6.8 <= 6.8.10affected
AutomatticWordPress6.7 <= 6.7.9affected
AutomatticWordPress6.6 <= 6.6.9affected

Weaknesses

  • CWE-201: CWE-201 Insertion of Sensitive Information Into Sent Data

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References