CVE-2025-12521

The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0.3 via the Analytify Tag HTML details. This makes it possible for unauthenticated attackers to extract usernames from source code. While we generally do not assign CVE IDs to username exposure issues, this vendor has specifically requested we consider it a vulnerability.
Configurations

No configuration.

History

31 Oct 2025, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-31 14:16

Updated : 2025-10-31 14:16


NVD link : CVE-2025-12521

Mitre link : CVE-2025-12521

CVE.ORG link : CVE-2025-12521


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor