The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 via the 'context_blog_modal_popup' due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.

Project Subscriptions

Vendors Products
Postmagthemes Subscribe
Context Blog Subscribe
Wordpress Subscribe
Wordpress Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 18 Feb 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Postmagthemes
Postmagthemes context Blog
Wordpress
Wordpress wordpress
Vendors & Products Postmagthemes
Postmagthemes context Blog
Wordpress
Wordpress wordpress

Wed, 18 Feb 2026 05:00:00 +0000

Type Values Removed Values Added
Description The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 via the 'context_blog_modal_popup' due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.
Title Context Blog <= 1.2.5 - Unauthenticated Private Post Disclosure
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-02-18T12:53:56.485Z

Reserved: 2025-10-22T14:12:09.205Z

Link: CVE-2025-12074

cve-icon Vulnrichment

Updated: 2026-02-18T12:26:34.735Z

cve-icon NVD

Status : Received

Published: 2026-02-18T05:16:16.950

Modified: 2026-02-18T05:16:16.950

Link: CVE-2025-12074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-18T10:32:59Z

Weaknesses