Junglewise Threat Intelligence

CVE-2026-39473: Pär Thernström Simple History sensitive data exposure

CVE-2026-39473 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

Simple History, a WordPress plugin used to track and log changes made within a website's dashboard, is vulnerable to a data exposure flaw. This vulnerability allows unauthorized individuals to view sensitive information that is normally restricted to administrators. An attacker could use this information to gain deeper insights into the site's configuration or facilitate further attacks.

Technical details

The Simple History plugin for WordPress (versions <= 5.24.0) contains a CWE-201 (Insertion of Sensitive Information Into Sent Data) vulnerability. The flaw allows for the retrieval of embedded sensitive data that should otherwise be restricted. The attack can be performed remotely over the network without any prior authentication or user interaction. This exposure typically occurs when sensitive information is inadvertently included in the plugin's output or logs accessible to unauthorized users. The issue is resolved in version 5.24.1.

Affected products

  • Pär Thernström Simple History <= 5.24.0

Timeline

  • 2026-02-20: other: Vulnerability reported by researcher
  • 2026-03-22: advisory: Patchstack advisory published
  • 2026-04-08: disclosed: CVE published to NVD
  • 5.24.1: patched: Vulnerability fixed in version 5.24.1

References

Related threats