CVE-2026-66666: Automattic WordPress

Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress allows Retrieve Embedded Sensitive Data. This issue affects WordPress: from 7.1 through 7.1.2, from 7.0 through 7.0.6, from 6.9 through 6.9.9, from 6.8 through 6.8.10, from 6.7 through 6.7.9, and from 6.6 through 6.6.9.

Affected products

  • Automattic WordPress: from 7.1, up to and including 7.1.2; from 7.0, up to and including 7.0.6; from 6.9, up to and including 6.9.9; from 6.8, up to and including 6.8.10; from 6.7, up to and including 6.7.9; from 6.6, up to and including 6.6.9

Published 2026-10-06. Last modified 2026-10-06.