Press release
WordPress "Timeleaks": when an image you thought was private is public
Most people think 'draft' means private and 'delete' means gone. With media files hosted by popular blog and CMS systems, that's not always true.Cybersecurity researchers from Labs at ITRES have uncovered a systemic privacy flaw affecting millions of WordPress websites using the popular Jetpack plugin.
The discovery, dubbed "CMS Media Timeleaks," reveals that sensitive images, even those deleted or redacted by editors, often remain publicly indexed and accessible through automated sitemaps.
For years, website editors have operated under the assumption that replacing a sensitive image with another or deleting a block in the WordPress editor removes that content from public view.
The research from ITRES proves this is a dangerous misconception. Due to the way Jetpack generates image sitemaps, original, unredacted files remain "advertised" to search engines and scrapers, creating a significant Operational Security (OpSec) risk.
THE TIMELEAK ISSUE
The research identifies two primary ways data "leaks" through the digital timeline.
1. Leaking the Past: An editor replaces a sensitive screenshot with a blurred version. While the blog post looks safe, Jetpack's sitemap continues to provide a direct link to the original, unredacted file.
2. Leaking the Future: Images uploaded to a "Draft" post (such as internal diagrams or confidential research) are often assigned a public URL and remain reachable before the article is published.
WHY THIS MATTERS
If a team uploads screenshots, drafts, or sensitive material, this can accidentally expose internal documents, unreleased announcements, private/pre-redacted screenshots or any kind of prívate data.
A DESIGN FLAW, NOT A BUG
When reported to Automattic (the creators of WordPress.com and Jetpack), the vendor stated the behavior is "working as intended," noting that media attachments are public by default.
"This is a classic mismatch between how software is built and how humans actually use it," says the research team at ITRES. "Engineers see a feature; a cybersecurity professional sees a confidentiality flaw. If you redact a document, you expect the secret to be gone. In the current CMS model, that secret is often just one click away in a hidden list."
DETECTION AND IMPACT
The researchers performed a shallow scan of over 20,000 websites and confirmed the leak is widespread, affecting everything from personal blogs to high-profile cybersecurity firms. To help the community, ITRES has released JetGhost, an open-source tool that allows website owners to scan their own sitemaps for "ghost" images.
Full Analysis: https://labs.itresit.es/2025/12/17/cms-media-timeleaks-jetpack-wordpress
Detection tool:
https://github.com/itres-labs/JetGhost-Suite
ITRESIT SOLUCIONES INFORMATICAS SL
Avenida de Murcia 23 Bajo
30110 · Cabezo de Torres, Murcia
+34 868 300 513
Eva Adanez - Marketing Manager
marketing@itresit.es
Labs at ITRES is the offensive research division of ITRES, a leading European cybersecurity firm specializing in pentesting, incident response, and advanced threat intelligence. They focus on identifying systemic flaws in modern digital infrastructure to help organizations stay one step ahead of emerging threats.
This release was published on openPR.
Permanent link to this press release:
Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.
You can edit or delete your press release WordPress "Timeleaks": when an image you thought was private is public here
News-ID: 4323623 • Views: …
More Releases for WordPress
Naprawa WordPress Company Specializes In WordPress And WooCommerce Solutions
Image: https://www.getnews.info/wp-content/uploads/2024/12/1733460763.jpg
Pomoc WordPress specializes in professional WordPress services, including website creation, WooCommerce store development, and optimization. The company offerings include expert troubleshooting, malware removal, regular updates, and specialized WordPress hosting.
Pomoc WordPress and Christopher Kowalsky are pleased to announce that they offer various Wordpress-related solutions for clients. The skills and experience of the repair (Naprawa WordPress [https://wordpress24h.pl/]) professionals provide clients with solutions for expert troubleshooting, malware removal, regular updates, and specialized…
WordPress SEO Specialist: Providing the Best WordPress SEO Services
WordPress SEO Specialist is proud to announce its commitment to delivering top-notch SEO services tailored specifically for WordPress websites. With a team of seasoned experts and a track record of success, WordPress SEO Specialist is poised to help businesses maximize their online presence and achieve their digital marketing goals.
As more businesses turn to WordPress for their website needs, the demand for specialized SEO services has never been greater. Recognizing this…
Get the Best WordPress web design at Lucrative WordPress startup packages
It is guaranteed; with The Website Creators, any business person can get 100% satisfaction, from on-point delivery to a meticulously designed website. If you are looking for good WordPress designers then this company might give you the benefits that you have been looking for. From their brilliant success stories to the highly indulging and extremely satisfying results offered by this company. They are a team of award-winning website experts and…
Australia WordPress websites and WooCommerce eCommerce solution WordPress Develo …
We're a leading web design company offering branding, web design, web development and digital marketing that deliver real results for our clients.
Creative, intelligent and useful design for organisations that make a difference
We're a design studio that works on web, print, publications and brand identity projects
Discovery
Understanding you
We'll question everything making sure to explore every option, giving you a website strategy that's been properly stress-tested.
2.
Design
Designing your user experience
We'll design a fully custom…
DesignStudio London New York Sydney Shanghai WordPress Design WordPress Developm …
We're built up of a team of experienced Web Developers, UX Designers, Project Managers and Paid Ads Specialists. Each of our team members are specialists in their chosen field and regularly participate in ongoing training to ensure that we're able to bring value to each project that we work on. Our team enjoys taking the time to get to know your vision and understand your objectives in order to recommend…
MilesWeb Launches Brand New WordPress Cloud Hosting Plans for WordPress Web Prof …
MilesWeb, the market leader and top-ranking web hosting provider, recently announced the launch of a brand new range of WordPress cloud hosting plans, a powerful platform designed exclusively for blogs, online stores and high-traffic WordPress sites.
With over a decade of experience in providing exceptional web hosting service, security, and support, MilesWeb is a customer-oriented company. They always strive to stay in step with the needs and wants of their customers.…
