
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66126 is a sensitive data exposure vulnerability (CWE-201: Insertion of Sensitive Information Into Sent Data) affecting the "Fix Media Library" WordPress plugin (slug: wow-media-library-fix) developed by wowpress.host. The vulnerability affects all versions up to and including 2.0, allowing unauthenticated remote attackers to retrieve embedded sensitive data. It was disclosed on December 16, 2025, with Patchstack as the assigning CNA. The CVSS v3.1 base score is 5.3 (Medium), as assessed by Patchstack (Patchstack).
The vulnerability is classified under CWE-201 (Insertion of Sensitive Information Into Sent Data), meaning the plugin inadvertently includes sensitive information in data transmitted to clients or external parties. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The specific mechanism involves the plugin embedding sensitive data within its responses or sent data in a way that can be retrieved by unauthorized parties. No detailed technical write-up or proof-of-concept code has been publicly released at this time (Patchstack).
Successful exploitation results in a limited confidentiality impact — an unauthenticated attacker can retrieve sensitive information embedded in data sent by the plugin, such as configuration details, internal paths, or other data not intended for public exposure. There is no integrity or availability impact. The scope is limited to the affected WordPress installation, and while lateral movement potential is low, exposed sensitive data could facilitate further targeted attacks against the site or its infrastructure (Patchstack).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2025-66126. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The low barrier to exploitation (no authentication or user interaction required) could attract opportunistic scanning, but the limited impact reduces attacker incentive (Patchstack).
Users of the Fix Media Library WordPress plugin should update to a version beyond 2.0 if a patched release is available, or deactivate and remove the plugin until a fix is provided by the vendor (wowpress.host). Site administrators should review their WordPress plugin inventory and monitor the Patchstack advisory page for patch availability. As a general hardening measure, restrict access to WordPress admin and plugin endpoints where possible, and audit plugin-generated HTTP responses for unintended data exposure (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."