WordPress Core, a popular website building platform, has a security flaw that can put sensitive information at risk. This flaw affects versions up to 6.4.3 and is caused by the redirect_guess_404_permalink function. Attackers who are not authenticated can use this vulnerability to reveal the title of a custom post that has been set to ‘private’.