/Vulnerability Library

WordPress Varnish/Nginx Proxy Caching <= 1.8.3 - Information Exposure

CVE-2025-62126
Verified

Description

Razvan Stanga Varnish/Nginx Proxy Caching <= 1.8.3 contains an insertion of sensitive information into sent data vulnerability caused by improper handling of embedded sensitive data, letting attackers retrieve sensitive information, exploit requires crafted requests.

Severity

Medium

CVSS Score

5.3

Exploit Probability

1%

Affected Product

varnish-caching-wordpress-plugin

Published Date

March 26, 2026

Template Author

pussycat0x

CVE-2025-62126.yaml
5.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2025-62126
CWE ID:
cwe-200

References

https://github.com/razvanstanga/varnish-caching-wordpress-plugin/pull/15https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/vcaching/varnishnginx-proxy-caching-183-unauthenticated-information-exposurehttps://nvd.nist.gov/vuln/detail/CVE-2025-62126

Remediation Steps

Update to the latest version beyond 1.8.3.