CVE-2025-67621

7.5

10up · Eight Day Week Print Workflow

The Eight Day Week Print Workflow plugin for WordPress is vulnerable to the exposure of sensitive system information, allowing authenticated users to retrieve embedded sensitive data.

Executive summary

A vulnerability in the 10up Eight Day Week Print Workflow plugin allows authenticated users to access sensitive system data, posing a moderate risk to information confidentiality.

Vulnerability

This flaw is classified as an exposure of sensitive system information (CWE-497), which can be triggered by an authenticated user with low privileges to retrieve embedded sensitive data.

Business impact

Successful exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive system information, which may provide an attacker with insights necessary for further malicious activity. With a CVSS score of 7.5, the vulnerability is classified as High, indicating that while it requires authentication, the potential for data compromise is significant enough to warrant immediate attention.

Remediation

Immediate Action: Review the official Patchstack advisory for any available updates and apply the latest version of the Eight Day Week Print Workflow plugin immediately.

Proactive Monitoring: Monitor server access logs for anomalous requests originating from authenticated user accounts that target sensitive system file paths or configuration data.

Compensating Controls: Implement a Web Application Firewall (WAF) to restrict access to sensitive plugin endpoints and monitor for unusual traffic patterns associated with the affected plugin.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the High severity rating and the potential for sensitive information disclosure, organizations should prioritize updating the Eight Day Week Print Workflow plugin as soon as a patch is released. If an update is not currently available, administrators should consider disabling the plugin or restricting access to the affected functionality until a vendor-supplied fix is applied.

Sources

Originally found and disclosed by PPzzAArr | Patchstack Bug Bounty Program, per the CVE Program record.