theme

Context Blog Vulnerabilities

3 known security issues reported for the Context Blog WordPress theme. Most recent disclosed Jul 10, 2026.

2 medium

Running Context Blog on your site? Check whether your installed version is affected.

Scan your site free

Context Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'postID' Parameter

medium

The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog_modal_popup. This makes it possible for unauthenticated attackers to extract the content of password-protected posts.

CVSS:
5.3
Affected:
up to 1.3.5
Fixed in:
1.3.6
Disclosed:
Jul 10, 2026

CVE-2026-6801 on NVD →

Context Blog [context-blog] < 1.2.6

unknown

[en] The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 via the 'context_blog_modal_popup' due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, pr...

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Feb 18, 2026

CVE-2025-12074 on NVD →

Context Blog <= 1.2.5 - Unauthenticated Private Post Disclosure

medium

The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 via the 'context_blog_modal_popup' due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private...

CVSS:
5.3
Affected:
up to 1.2.5
Fixed in:
1.2.6
Disclosed:
Feb 17, 2026

CVE-2025-12074 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database