CVE-2026-66666: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-66666 is a sensitive data exposure vulnerability (CWE-201: Insertion of Sensitive Information Into Sent Data) in Automattic WordPress that allows unauthenticated remote attackers to retrieve embedded sensitive data from comment feeds. It affects WordPress versions 6.6 through 6.6.9, 6.7 through 6.7.9, 6.8 through 6.8.10, 6.9 through 6.9.9, 7.0 through 7.0.6, and 7.1 through 7.1.2. The vulnerability was disclosed and patched on October 6, 2026, as part of the WordPress 7.1.3 security release. It carries a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Patchstack).

Technical details

The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data). Specifically, for single-post comment feeds, WP_Query loaded a post's comments before checking whether the requesting visitor had permission to view the post. The visibility check subsequently cleared the post object but not the already-loaded comments, and since comment feeds never return a 404, the feed would print comments from private or unpublished posts to unauthenticated visitors. No authentication, special configuration, or user interaction is required to exploit this flaw — an attacker simply needs to request the comment feed for a private or unpublished post (Patchstack, GitHub Advisory).

Impact

Successful exploitation allows unauthenticated network attackers to read comments on private and unpublished WordPress posts, which may contain sensitive editorial discussions, internal notes, credentials, or other confidential information not intended for public disclosure. The impact is limited to confidentiality — there is no integrity or availability impact, and no lateral movement capability is directly enabled by this vulnerability. The attack is automatable and network-accessible, making it feasible to scan and harvest data from large numbers of vulnerable WordPress installations (GitHub Advisory, Patchstack).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, reflecting a very low current probability of exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The CVE status is listed as "Deferred" and the NVD SSVC assessment confirms no known exploitation at this time, though the attack is rated as automatable due to requiring no authentication or user interaction (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running affected versions (6.6.x through 7.1.2) using tools like Shodan, Censys, or WPScan to fingerprint WordPress version numbers.
  2. Enumerate post IDs: Use the WordPress REST API (/wp-json/wp/v2/posts) or standard WordPress URL patterns to enumerate post IDs, including those that may return limited metadata for private/unpublished posts.
  3. Request comment feed for target post: Craft an HTTP GET request to the comment feed endpoint for a specific post ID, e.g., https://target.example.com/?feed=rss2&p=<POST_ID>&post_type=post.
  4. Retrieve sensitive comments: If the target post is private or unpublished and has comments, the feed response will include those comments in plaintext XML, exposing their content to the unauthenticated requester.
  5. Harvest data at scale: Automate requests across a range of post IDs to systematically extract all accessible private post comments from the vulnerable site (Patchstack).

Indicators of compromise

  • Network: Unusual or high-volume HTTP GET requests to WordPress comment feed URLs (e.g., /?feed=rss2&p=<ID>) from a single IP or range of IPs, particularly targeting non-sequential or high-numbered post IDs.
  • Logs: Web server access logs showing repeated requests to /?feed=rss2 or /feed/ endpoints with varying p= parameters from unauthenticated clients (no session cookies); HTTP 200 responses to feed requests for posts that are private or in draft status.
  • Application Logs: WordPress debug logs (if enabled) showing WP_Query calls for comment feeds on private post IDs from unauthenticated sessions.

Mitigation and workarounds

The primary remediation is to update WordPress to a patched version: 6.6.10+, 6.7.10+, 6.8.11+, 6.9.10+, 7.0.7+, or 7.1.3+. WordPress 7.1.3 was released on October 6, 2026, and includes backports to older supported branches through at least 6.6. Sites with automatic background updates enabled will receive the patch automatically. As a temporary workaround prior to patching, administrators can disable comment feeds via Settings > Discussion or using a security plugin. After updating, administrators should audit private and unpublished posts for sensitive comments that may have been exposed (Patchstack, GitHub Advisory).

Community reactions

Patchstack researcher Ananda Dhakal was credited with discovering and reporting the private post comment disclosure vulnerability. Patchstack published a detailed security release breakdown characterizing the 7.1.3 release as a "maintenance and security release" with seven security fixes, noting that while the update is recommended, it is "not a drop-everything emergency" given the moderate severity and lack of active exploitation (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-66666MEDIUM6.9
  • wordpress
NoNoOct 06, 2026
CVE-2026-86851MEDIUM6.5
  • livees-checkout
NoNoOct 06, 2026
CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management