Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

Context Blog Theme for WordPress Exposes Sensitive Posts Data

CVE-2025-12074
Summary

The Context Blog theme for WordPress, versions 1.2.5 and earlier, allows unauthorized users to view sensitive posts, including password-protected, private, or draft content. This means that sensitive information may be exposed to anyone who knows how to exploit this weakness. To protect your site, update to the latest version of the theme or remove the vulnerable feature.

Original title
The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 via the 'context_blog_modal_popup' due to insufficient restrictions on which p...
Original description
The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 via the 'context_blog_modal_popup' due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.
nvd CVSS3.1 5.3
Vulnerability type
CWE-200 Information Exposure
Published: 18 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026