PT-2025-30228 · WordPress+1 · Wordpress+1

Yohann Sillam

·

Published

2025-07-21

·

Updated

2025-07-21

·

CVE-2025-54352

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress versions 3.5 through 6.8.2
Description WordPress versions 3.5 through 6.8.2 are susceptible to a flaw that allows remote attackers to determine the titles of private and draft posts through pingback.ping XML-RPC requests.
Recommendations Update to version 6.8.3. Disable pingbacks.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-54352

Affected Products

Debian
Wordpress