CVE-2026-42379
7.7WPDeveloper · Templately
The Templately plugin for WordPress is susceptible to an insertion of sensitive information into sent data, allowing attackers to retrieve embedded sensitive data.
Executive summary
An authenticated sensitive data exposure vulnerability in the WPDeveloper Templately plugin poses a significant risk to organizational data privacy.
Vulnerability
This vulnerability, categorized as CWE-201, allows an authenticated user with low-level privileges to access and retrieve sensitive data that should not be exposed. The flaw exists due to improper handling of information during data transmission processes within the plugin.
Business impact
The exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive business or user information, potentially resulting in data breaches and compliance violations. With a CVSS score of 7.7, the risk is classified as High, reflecting the potential for significant impact on data confidentiality despite the requirement for authenticated access.
Remediation
Immediate Action: Update the WordPress Templately plugin to version 3.6.2 or later to apply the vendor-supplied security patch.
Proactive Monitoring: Review web server access logs for anomalous requests directed at the Templately plugin endpoints, specifically looking for unexpected data retrieval patterns.
Compensating Controls: Utilize a Web Application Firewall (WAF) to filter malicious requests, although immediate patching remains the primary requirement to fully address the underlying flaw.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available in the provided data.
Analyst recommendation
The high severity of this vulnerability necessitates immediate action. Administrators must prioritize updating the Templately plugin to the latest version, 3.6.2, to eliminate the risk of sensitive data exposure. Failure to apply this update leaves the application environment vulnerable to unauthorized data retrieval by authenticated actors.
Sources
Originally found and disclosed by Ananda Dhakal | Patchstack, per the CVE Program record.