CVE-2025-54352

Source
https://cve.org/CVERecord?id=CVE-2025-54352
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54352.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-54352
Downstream
Published
2025-07-21T05:15:38Z
Modified
2026-04-10T05:29:32.280714Z
Summary
[none]
Details

WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.

References

Affected packages