CVE-2025-68033
7.5Brecht · Custom Related Posts
The Custom Related Posts plugin for WordPress contains an insertion of sensitive information into sent data vulnerability, allowing unauthenticated attackers to retrieve embedded sensitive data.
Executive summary
An unauthenticated sensitive data exposure vulnerability in the Custom Related Posts plugin for WordPress poses a significant risk to information confidentiality.
Vulnerability
The plugin fails to properly restrict access to sensitive information, allowing an unauthenticated attacker to retrieve embedded data through the affected component via a network-based attack vector.
Business impact
The exploitation of this vulnerability allows unauthorized parties to access sensitive information that should otherwise be protected, potentially leading to data leaks or the exposure of internal system configurations. With a CVSS score of 7.5, this high-severity flaw represents a significant risk to organizational data privacy and regulatory compliance.
Remediation
Immediate Action: Since a specific patch version is not currently identified, users should disable or remove the Custom Related Posts plugin until an official update resolving this issue is released by the vendor.
Proactive Monitoring: Review web server and application access logs for unusual patterns of requests directed at the plugin endpoints, particularly those originating from unauthorized or external IP addresses.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to inspect and block suspicious outbound traffic or unauthorized requests targeting WordPress plugin directories.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for unauthenticated data exfiltration, organizations should treat this vulnerability with urgency. Administrators must audit their WordPress installations to identify instances of the Custom Related Posts plugin and implement the recommended deactivation strategy until a secure version is available.
Sources
Originally found and disclosed by MD ISMAIL | Patchstack Bug Bounty Program, per the CVE Program record.