CVE-2025-57923

An Insertion of Sensitive Information into Sent Data vulnerability in the Ideal Postcodes UK Address Postcode Validation WordPress plugin exposes the API key, allowing unauthorized third parties to retrieve and reuse the key across any domain. Since API keys are unrestricted by default, with the “Allowed URLs” field left empty upon creation of API key this can lead to unauthorized use and depletion of API credits.Note: the vulnerability is assessed based on the default configuration.This issue affects UK Address Postcode Validation: from n/a through 3.9.2.
Configurations

No configuration.

History

24 Oct 2025, 16:17

Type Values Removed Values Added
References
  • {'url': 'https://web.archive.org/web/20250807222539/https://docs.ideal-postcodes.co.uk/docs/guides/api-key-secure', 'source': 'audit@patchstack.com'}
Summary (en) An Insertion of Sensitive Information into Sent Data vulnerability in the Ideal Postcodes UK Address Postcode Validation WordPress plugin exposes the API key, allowing unauthorized third parties to retrieve and reuse the key across any domain. Since API keys are unrestricted by default, with the “Allowed URLs” field left empty upon creation of API key this can lead to unauthorized use and depletion of API credits. Note: the vulnerability is assessed based on the default configuration. This issue affects UK Address Postcode Validation: from n/a through 3.9.2. (en) An Insertion of Sensitive Information into Sent Data vulnerability in the Ideal Postcodes UK Address Postcode Validation WordPress plugin exposes the API key, allowing unauthorized third parties to retrieve and reuse the key across any domain. Since API keys are unrestricted by default, with the “Allowed URLs” field left empty upon creation of API key this can lead to unauthorized use and depletion of API credits.Note: the vulnerability is assessed based on the default configuration.This issue affects UK Address Postcode Validation: from n/a through 3.9.2.

24 Oct 2025, 04:15

Type Values Removed Values Added
Summary (en) Insertion of Sensitive Information Into Sent Data vulnerability in Ideal Postcodes UK Address Postcode Validation allows Retrieve Embedded Sensitive Data. This issue affects UK Address Postcode Validation: from n/a through 3.9.2. (en) An Insertion of Sensitive Information into Sent Data vulnerability in the Ideal Postcodes UK Address Postcode Validation WordPress plugin exposes the API key, allowing unauthorized third parties to retrieve and reuse the key across any domain. Since API keys are unrestricted by default, with the “Allowed URLs” field left empty upon creation of API key this can lead to unauthorized use and depletion of API credits. Note: the vulnerability is assessed based on the default configuration. This issue affects UK Address Postcode Validation: from n/a through 3.9.2.
References
  • () https://web.archive.org/web/20250807222539/https://docs.ideal-postcodes.co.uk/docs/guides/api-key-secure -

22 Sep 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-22 19:15

Updated : 2025-10-24 16:17


NVD link : CVE-2025-57923

Mitre link : CVE-2025-57923

CVE.ORG link : CVE-2025-57923


JSON object : View

Products Affected

No product.

CWE
CWE-201

Insertion of Sensitive Information Into Sent Data