Sceawere

Vulnerability Detail

CVE-2026-66435UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Rollback Sensitive Data Exposure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
2h ago
Vendor
Devin Walker
Product
WP Rollback
Attack Type
Insertion of Sensitive Information Into Sent Data
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Insertion of Sensitive Information Into Sent Data vulnerability in Devin Walker WP Rollback wp-rollback allows Retrieve Embedded Sensitive Data.This issue affects WP Rollback: from n/a through 3.1.2.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-10-10T14:16:38.000Z",
  "pubdate": "2026-10-10T14:16:38.000Z",
  "executiveSummary": "This vulnerability, classified as an 'Insertion of Sensitive Information Into Sent Data' flaw, resides within the WP Rollback plugin by Devin Walker.\nThe security defect allows an unauthorized party to retrieve embedded sensitive information from data sent by the plugin during its operational processes.\nThe vulnerability affects all versions of WP Rollback from n/a through 3.1.2.\nThe primary risk involves the potential exposure of sensitive data transmitted by the plugin, which could be intercepted or leaked due to improper handling of information within the data sent during plugin activity.\nAn attacker does not necessarily require highly elevated privileges if they can intercept or access the improperly sent data stream.\nThe exposure necessitates immediate attention to prevent unauthorized access to potentially confidential system information.",
  "technicalDetails": "The vulnerability originates from the improper sanitization or handling of data structures within the WP Rollback plugin's reporting or communication mechanisms. When the plugin processes requests—specifically those related to the rollback functionality—it inadvertently includes sensitive data within the output stream or sent data packets.\nThe root cause is identified as an 'Insertion of Sensitive Information Into Sent Data' weakness, where the plugin mechanism fails to strip or redact sensitive configuration details or embedded secrets before the data is prepared for transmission.\nAttack flow involves the interception of communication originating from the plugin. Since the plugin performs operations that interact with the WordPress environment, the data sent often contains internal paths, configuration metadata, or other system-level details that are not intended for external consumption.\nThe vulnerable component handles the data preparation logic prior to the transmission of diagnostic or functional information. By failing to validate the contents of the payload, the component facilitates the exfiltration of system-specific information.\nAuthentication requirements and the precise network exposure depend on the environment; however, if the data is sent to external endpoints or logged in a location accessible to unauthorized users, the requirement for exploitation is minimized.\nPost-exploitation impact includes information disclosure, where an attacker gains insights into the site's internal configuration, file structure, or sensitive environment variables. This intelligence facilitates further targeted attacks, such as privilege escalation or the identification of additional vectors for system compromise.\nThe flaw manifests across the version range n/a to 3.1.2, indicating a long-standing omission in the input/output data handling policies of the plugin."
}
CVE-2026-66435: WP Rollback Sensitive Data Exposure (MEDIUM Severity, CVSS: 5.9) | Sceawere