CVE-2026-66666

NameCVE-2026-66666
DescriptionInsertion of Sensitive Information Into Sent Data vulnerability in Aut ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wordpress (PTS)bookworm, bookworm (security)6.1.9+dfsg1-0+deb12u1vulnerable
trixie6.8.7+dfsg1-0+deb13u1vulnerable
trixie (security)6.8.10+dfsg1-0+deb13u1vulnerable
forky, sid7.1.2+dfsg1-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
wordpresssource(unstable)(unfixed)

Notes

check, https://patchstack.com/database/wordpress/wordpress/wordpress/vulnerability/wordpress-wordpress-wordpress-7-1-2-sensitive-data-exposure-vulnerability?_s_id=cve claims to be fixed in future 7.1.3

Search for package or bug name: Reporting problems