Back to Database
Status published
Low
CVE-2025-54352
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles...
Vulnerability Description
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-54352
Credits & Attribution
No credits recorded in the NVD database.
More from WordPress
View All →CVE-2025-58674
WordPress <= 6.8.2 - (Author+) Cross Site Scripting (XSS) Vulnerability
Medium
5.9
CVE-2025-58246
WordPress <= 6.8.2 - (Contributor+) Sensitive Data Exposure Vulnerability
Medium
4.3
CVE-2024-31211
Remote Code Execution in `WP_HTML_Token`
Medium
5.5
CVE-2024-31210
PHP file upload bypass via Plugin installer
High
7.7
CVE-2023-5561
WordPress < 6.3.2 - Unauthenticated Post Author Email Disclosure
Unknown
0
Affected Vendor
WordPress
View all reports →Affected Software
WordPress
Vulnerable Versions:
3.5
Timeline
Official Publish:
July 21st, 2025
Last Modified:
July 21st, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.