
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-42379 is a Sensitive Data Exposure vulnerability (CWE-201: Insertion of Sensitive Information Into Sent Data) in the WPDeveloper Templately WordPress plugin. It affects all versions of Templately through 3.6.1, allowing authenticated attackers with low privileges to retrieve sensitive information embedded in sent data. The vulnerability was discovered by Ananda Dhakal of Patchstack, reported on April 20, 2026, and publicly disclosed on April 27, 2026. It carries a CVSS v3.1 base score of 7.7 (High) (Patchstack, GitHub Advisory).
The vulnerability is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data), meaning the plugin transmits data to another actor while inadvertently including sensitive information that should not be accessible to that actor. Exploitation requires network access with low-level authenticated privileges (e.g., Contributor or Developer role), no user interaction, and results in a scope change — meaning the impact extends beyond the vulnerable component itself. No specific technical write-up or proof-of-concept code detailing the exact data transmission mechanism has been publicly released (Patchstack, GitHub Advisory).
Successful exploitation allows authenticated low-privileged users to retrieve sensitive information embedded in plugin-sent data, resulting in a high confidentiality impact with no integrity or availability impact. The changed scope indicates that the exposed data may affect resources or components beyond the Templately plugin itself, potentially enabling further attacks against the WordPress installation or its users. This type of information disclosure can be leveraged to escalate privileges or exploit other weaknesses in the system (Patchstack).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at the time of disclosure. The EPSS score is approximately 0.039% (12th percentile), indicating a low near-term exploitation probability. No threat actor attribution or CISA KEV catalog listing has been identified for this vulnerability (GitHub Advisory, Patchstack).
The primary remediation is to update the Templately WordPress plugin to version 3.6.2 or later, which contains the patch for this vulnerability. For sites unable to immediately update, administrators should implement access controls to restrict authenticated user roles (e.g., Contributor) from accessing Templately functionality, and consider network segmentation to limit exposure. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically (Patchstack).
The vulnerability was covered in Wordfence's weekly WordPress vulnerability report for the period of April 27 to May 3, 2026, indicating routine tracking by the WordPress security community. Patchstack classified the vulnerability as low priority with unlikely exploitation potential, and social media mentions were limited to automated CVE notification accounts. No significant vendor statements or notable researcher commentary beyond the initial Patchstack disclosure have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."