Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPXPO PostX ultimate-post allows Retrieve Embedded Sensitive Data.This issue affects PostX: from n/a through <= 5.0.3.
Published: 2025-12-24
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in the PostX Ultimate‑Post plugin allows an attacker to download or view sensitive information stored by the site. The flaw is a classic data‑exposure weakness (CWE‑497) that permits retrieval of embedded data that should remain confidential. A successful exploitation would cause confidentiality loss for the site’s data but does not compromise code execution or availability.

Affected Systems

WPXPO PostX Ultimate‑Post plugin, any installation whose version is 5.0.3 or earlier. No version higher than 5.0.3 is impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is below 1%, suggesting that the likelihood of automated exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the publicly exposed web interface of the WordPress site, where any user can send a request that triggers the data‑extraction logic. No additional setup or privileged access appears to be required beyond normal public access to the site.

Generated by OpenCVE AI on April 29, 2026 at 15:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the PostX Ultimate‑Post plugin to a version newer than 5.0.3
  • Disable or remove the plugin if it is not needed for site functionality
  • Deploy a web application firewall rule to block or restrict requests that attempt to traverse to the data endpoints exposed by the plugin

Generated by OpenCVE AI on April 29, 2026 at 15:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpxpo
Wpxpo postx
Vendors & Products Wordpress
Wordpress wordpress
Wpxpo
Wpxpo postx

Wed, 24 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 13:15:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPXPO PostX ultimate-post allows Retrieve Embedded Sensitive Data.This issue affects PostX: from n/a through <= 5.0.3.
Title WordPress PostX plugin <= 5.0.3 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:31.303Z

Reserved: 2025-12-19T10:20:18.891Z

Link: CVE-2025-68606

cve-icon Vulnrichment

Updated: 2025-12-24T18:43:28.344Z

cve-icon NVD

Status : Deferred

Published: 2025-12-24T13:16:28.197

Modified: 2026-04-27T19:16:36.413

Link: CVE-2025-68606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T15:30:14Z

Weaknesses