PT-2025-29216 · WordPress · Woodmart
Matthew Rollings
·
Published
2025-07-11
·
Updated
2025-07-11
·
CVE-2025-6745
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
WoodMart versions prior to 8.2.6
Description:
The WoodMart plugin for WordPress is vulnerable to Information Exposure in versions prior to 8.2.6 due to insufficient restrictions on post inclusion within the
woodmart get posts by query() function. This allows unauthenticated attackers to extract data from password-protected, private, or draft posts without authorization.Recommendations:
Update WoodMart to version 8.2.6 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woodmart