
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-66666 is a sensitive data exposure vulnerability (CWE-201: Insertion of Sensitive Information Into Sent Data) in Automattic WordPress that allows unauthenticated remote attackers to retrieve embedded sensitive data from comment feeds. It affects WordPress versions 6.6 through 6.6.9, 6.7 through 6.7.9, 6.8 through 6.8.10, 6.9 through 6.9.9, 7.0 through 7.0.6, and 7.1 through 7.1.2. The vulnerability was disclosed and patched on October 6, 2026, as part of the WordPress 7.1.3 security release. It carries a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Patchstack).
The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data). Specifically, for single-post comment feeds, WP_Query loaded a post's comments before checking whether the requesting visitor had permission to view the post. The visibility check subsequently cleared the post object but not the already-loaded comments, and since comment feeds never return a 404, the feed would print comments from private or unpublished posts to unauthenticated visitors. No authentication, special configuration, or user interaction is required to exploit this flaw — an attacker simply needs to request the comment feed for a private or unpublished post (Patchstack, GitHub Advisory).
Successful exploitation allows unauthenticated network attackers to read comments on private and unpublished WordPress posts, which may contain sensitive editorial discussions, internal notes, credentials, or other confidential information not intended for public disclosure. The impact is limited to confidentiality — there is no integrity or availability impact, and no lateral movement capability is directly enabled by this vulnerability. The attack is automatable and network-accessible, making it feasible to scan and harvest data from large numbers of vulnerable WordPress installations (GitHub Advisory, Patchstack).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, reflecting a very low current probability of exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The CVE status is listed as "Deferred" and the NVD SSVC assessment confirms no known exploitation at this time, though the attack is rated as automatable due to requiring no authentication or user interaction (Feedly).
/wp-json/wp/v2/posts) or standard WordPress URL patterns to enumerate post IDs, including those that may return limited metadata for private/unpublished posts.https://target.example.com/?feed=rss2&p=<POST_ID>&post_type=post./?feed=rss2&p=<ID>) from a single IP or range of IPs, particularly targeting non-sequential or high-numbered post IDs./?feed=rss2 or /feed/ endpoints with varying p= parameters from unauthenticated clients (no session cookies); HTTP 200 responses to feed requests for posts that are private or in draft status.WP_Query calls for comment feeds on private post IDs from unauthenticated sessions.The primary remediation is to update WordPress to a patched version: 6.6.10+, 6.7.10+, 6.8.11+, 6.9.10+, 7.0.7+, or 7.1.3+. WordPress 7.1.3 was released on October 6, 2026, and includes backports to older supported branches through at least 6.6. Sites with automatic background updates enabled will receive the patch automatically. As a temporary workaround prior to patching, administrators can disable comment feeds via Settings > Discussion or using a security plugin. After updating, administrators should audit private and unpublished posts for sensitive comments that may have been exposed (Patchstack, GitHub Advisory).
Patchstack researcher Ananda Dhakal was credited with discovering and reporting the private post comment disclosure vulnerability. Patchstack published a detailed security release breakdown characterizing the 7.1.3 release as a "maintenance and security release" with seven security fixes, noting that while the update is recommended, it is "not a drop-everything emergency" given the moderate severity and lack of active exploitation (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."