CVE-2026-66666 Overview
CVE-2026-66666 is a sensitive information disclosure vulnerability in Automattic WordPress that allows unauthenticated remote attackers to retrieve embedded sensitive data over the network. The flaw is classified under [CWE-201: Insertion of Sensitive Information Into Sent Data] and stems from WordPress returning data in outbound responses that should not be exposed to anonymous requesters. The issue affects multiple WordPress branches, including the 7.1.x, 7.0.x, 6.9.x, 6.8.x, 6.7.x, and 6.6.x release lines. Automattic addressed the defect in the WordPress 7.1.3 maintenance and security release.
Critical Impact
Unauthenticated network attackers can retrieve embedded sensitive data from vulnerable WordPress sites without any user interaction or privileges.
Affected Products
- Automattic WordPress 7.1 through 7.1.2
- Automattic WordPress 7.0 through 7.0.6, 6.9 through 6.9.9, and 6.8 through 6.8.10
- Automattic WordPress 6.7 through 6.7.9 and 6.6 through 6.6.9
Discovery Timeline
- 2026-10-06 - CVE CVE-2026-66666 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-66666
Vulnerability Analysis
The vulnerability is a sensitive information disclosure flaw mapped to [CWE-201]. WordPress embeds data into responses that are returned to unauthenticated clients, exposing information that should remain restricted to privileged users. An attacker interacts with the site over the network and parses the server response to extract the embedded fields. No authentication, user interaction, or elevated privileges are required to trigger the behavior.
The disclosure affects confidentiality only. Server integrity and availability are not impacted, and the issue does not grant code execution or write access. However, exposed data can facilitate follow-on attacks such as credential targeting, account enumeration, or privilege-aware exploitation against the same site.
Root Cause
The root cause is improper filtering of response payloads. WordPress inserts fields intended for authorized contexts into responses served to unauthenticated requesters. Patchstack and WordPress.org attribute the fix to tighter output scoping in the WordPress 7.1.3 release.
Attack Vector
Exploitation occurs over the network against an internet-reachable WordPress site. An attacker issues standard HTTP requests to endpoints that return the embedded sensitive fields and parses the response. Because no authentication is required, mass scanning of exposed WordPress sites is feasible. See the Patchstack WordPress 7.1.2 Data Exposure Vulnerability advisory for technical details.
No verified public proof-of-concept code is available at the time of writing.
Detection Methods for CVE-2026-66666
Indicators of Compromise
- Unauthenticated HTTP GET requests to WordPress REST API endpoints (/wp-json/) returning fields that include user, configuration, or embedded metadata not expected in anonymous responses.
- Repeated enumeration patterns from a single source IP targeting multiple WordPress endpoints in short time windows.
- Scraping activity from known scanner user agents or anonymizing infrastructure against WordPress sites running affected versions.
Detection Strategies
- Inventory WordPress installations and flag any instance running a version in the vulnerable ranges (7.1–7.1.2, 7.0–7.0.6, 6.9–6.9.9, 6.8–6.8.10, 6.7–6.7.9, 6.6–6.6.9).
- Inspect web server and WAF logs for anonymous requests to REST API routes returning unusually large response bodies.
- Correlate outbound response content with expected schemas and alert when sensitive fields appear in unauthenticated responses.
Monitoring Recommendations
- Enable verbose access logging on the WordPress front end and ship logs to a central analytics pipeline for retention and search.
- Baseline normal REST API response sizes and alert on statistical deviations that may indicate data exposure.
- Monitor for credential stuffing, account takeover, or targeted phishing against users whose metadata may have been leaked.
How to Mitigate CVE-2026-66666
Immediate Actions Required
- Upgrade all WordPress installations to version 7.1.3 or later as described in the WordPress 7.1.3 Maintenance and Security Release.
- Audit exposed REST API endpoints and disable or restrict any that are not required by the site.
- Rotate credentials and API tokens for accounts whose metadata may have been disclosed through unauthenticated responses.
Patch Information
Automattic released WordPress 7.1.3 as a maintenance and security release that remediates CVE-2026-66666. Administrators should apply the update through the WordPress admin dashboard, WP-CLI, or their managed hosting provider. Refer to the Patchstack WordPress 7.1.3 Security Release notes for release contents.
Workarounds
- Place a web application firewall in front of WordPress to block unauthenticated requests to sensitive REST API routes until patching is complete.
- Use WordPress hooks or a hardening plugin to restrict /wp-json/ responses to authenticated sessions where business requirements permit.
- Limit public exposure of staging, backup, and legacy WordPress instances until they are upgraded to a fixed version.
# Configuration example: upgrade WordPress using WP-CLI
wp core update --version=7.1.3 --force
wp core update-db
wp cache flush
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.