Information disclosure in WordPress - CVE-2020-25286
Published: September 13, 2020 / Updated: September 22, 2020
WordPress
WordPress.ORG
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive data.
The
vulnerability exists due to improper access restrictions in
wp-includes/comment-template.php, as comments from a post or page could
sometimes be seen in the latest
comments even if the post or page was not public. A remote attacker can
gain access to sensitive information.