Impact
The vulnerability is an insertion of sensitive information into data sent from WordPress, allowing an attacker to retrieve embedded sensitive data from comments on private or unpublished posts. The flaw is a typical information‑exposure weakness (CWE‑201) that compromises confidentiality. The flaw can be exercised without authentication by requesting the comment feed URL. Because the feed is publicly reachable, anyone who can generate a request can see the data that belongs on a private or unpublished post, exposing potentially confidential user or site information. The CVSS score is 6.9, indicating moderate severity. No EPSS score is currently available, and the issue is not listed in the CISA KEV catalog. However, the lack of authentication requirements makes it straightforward to exploit once a vulnerable installation is identified. Organizations running unpatched WordPress Core versions should treat this as a real risk.
Affected Systems
WordPress Core by Automattic from any version up to and including 7.1.2 is vulnerable. The fix is provided in WordPress Core 7.1.3 and later. All deployments of WordPress Core versions 7.1.2 or older are affected and should be updated.
Risk and Exploitability
The vulnerability has a CVSS score of 6.9, which classifies it as moderate. EPSS data is not available, so the exploitation likelihood cannot be quantified, but the flaw exposes data through a publicly reachable endpoint, enabling straightforward unauthenticated data theft. The attack requires no special credentials or elevated privileges; simply accessing the comment feed URL on a vulnerable site is sufficient to extract the protected content.
OpenCVE Enrichment