Sploitus

CVE-2025-54352

4 known exploits for CVE-2025-54352

WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.

Affected products
Debian, Wordpress
CVSS 3.1
3.7 LOW
EPSS
0.3% (25th percentile)
Weakness
CWE-669
NVD status
Deferred
Published
2025-07-21
CVE-2025-54352 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2025-54352

Proof-of-concept code and exploit modules indexed by Sploitus