CVE-2026-42379
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-42379 is a Sensitive Data Exposure vulnerability (CWE-201: Insertion of Sensitive Information Into Sent Data) in the WPDeveloper Templately WordPress plugin. It affects all versions of Templately through 3.6.1, allowing authenticated attackers with low privileges to retrieve sensitive information embedded in sent data. The vulnerability was discovered by Ananda Dhakal of Patchstack, reported on April 20, 2026, and publicly disclosed on April 27, 2026. It carries a CVSS v3.1 base score of 7.7 (High) (Patchstack, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data), meaning the plugin transmits data to another actor while inadvertently including sensitive information that should not be accessible to that actor. Exploitation requires network access with low-level authenticated privileges (e.g., Contributor or Developer role), no user interaction, and results in a scope change — meaning the impact extends beyond the vulnerable component itself. No specific technical write-up or proof-of-concept code detailing the exact data transmission mechanism has been publicly released (Patchstack, GitHub Advisory).

Impact

Successful exploitation allows authenticated low-privileged users to retrieve sensitive information embedded in plugin-sent data, resulting in a high confidentiality impact with no integrity or availability impact. The changed scope indicates that the exposed data may affect resources or components beyond the Templately plugin itself, potentially enabling further attacks against the WordPress installation or its users. This type of information disclosure can be leveraged to escalate privileges or exploit other weaknesses in the system (Patchstack).

Exploitability

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at the time of disclosure. The EPSS score is approximately 0.039% (12th percentile), indicating a low near-term exploitation probability. No threat actor attribution or CISA KEV catalog listing has been identified for this vulnerability (GitHub Advisory, Patchstack).

Mitigation and workarounds

The primary remediation is to update the Templately WordPress plugin to version 3.6.2 or later, which contains the patch for this vulnerability. For sites unable to immediately update, administrators should implement access controls to restrict authenticated user roles (e.g., Contributor) from accessing Templately functionality, and consider network segmentation to limit exposure. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically (Patchstack).

Community reactions

The vulnerability was covered in Wordfence's weekly WordPress vulnerability report for the period of April 27 to May 3, 2026, indicating routine tracking by the WordPress security community. Patchstack classified the vulnerability as low priority with unlikely exploitation potential, and social media mentions were limited to automated CVE notification accounts. No significant vendor statements or notable researcher commentary beyond the initial Patchstack disclosure have been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-92541HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-92540HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-86785MEDIUM5.3
  • woo-to-facebook-shop
NoNoSep 20, 2026
CVE-2026-92965LOW3.7
  • tiktok-for-business
NoYesSep 20, 2026
CVE-2026-92423LOW2.7
  • meow-gallery
NoYesSep 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management