Title: Unpatch Security Issue
Last modified: October 23, 2025

---

# Unpatch Security Issue

 *  Resolved [ajreading](https://wordpress.org/support/users/ajreading/)
 * (@ajreading)
 * [9 months, 2 weeks ago](https://wordpress.org/support/topic/unpatch-security-issue/)
 * This plugin has an active vulnerability that has been reported a month ago. Are
   there any plans to patch this issue or should we be looking to find an alternative
   postcode data provider?

Viewing 5 replies - 1 through 5 (of 5 total)

 *  Plugin Author [Ideal Postcodes](https://wordpress.org/support/users/idealpostcodes/)
 * (@idealpostcodes)
 * [9 months, 2 weeks ago](https://wordpress.org/support/topic/unpatch-security-issue/#post-18692568)
 * Hi there
 * We have investigated the Patchstack report (CVE-2025-57923) and can provide immediate
   clarification:
 * The exposed Information is a public-facing API Key and is not a security risk.
 * We’ve clarified what the issue with Patchstack. We discovered the “sensitive 
   data” exposed by the plugin is a public-facing API key used for our address lookup
   service. This key is not a secret credential and does not pose a vulnerability
   to your site.
 * This method of using a publicly viewable key for address lookup is standard practice
   for API usage. Similar services like Google Maps and Mapbox also rely on public
   API keys. These keys serve primarily to identify and meter usage (for billing
   and rate limiting), rather than act as a secret for protecting private data.
 * If this were a real CVE, we would *immediately* ship a fix and notify customers.
   However there is no way to fix this because it is working as designed.
 * Patchstack’s last email to us was sent 6th October 2025, wanting to clarify where
   we documented API keys were public. We responded the same day with documentation
   demonstrating the “sensitive data” was in fact a public-facing API key. We received
   no reply.
 * We have sent 5 emails between then and today (23 October) asking they either 
   correct the CVE or explain why this qualifies as a vulnerability in light of 
   the information we have provided. We have received no replies or even acknowledgement
   of these emails.
 * We will shortly be issuing a patch a breakdown of this CVE and Patchstack’s response
   to date. Given their lack of communication, we have also notified Patchstack’s
   CNA about this issue to resolve the CVE higher up.
    -  This reply was modified 9 months, 2 weeks ago by [Ideal Postcodes](https://wordpress.org/support/users/idealpostcodes/).
    -  This reply was modified 9 months, 2 weeks ago by [Ideal Postcodes](https://wordpress.org/support/users/idealpostcodes/).
 *  Thread Starter [ajreading](https://wordpress.org/support/users/ajreading/)
 * (@ajreading)
 * [9 months, 2 weeks ago](https://wordpress.org/support/topic/unpatch-security-issue/#post-18692689)
 * Thank you for very much for the prompt and detailed response. I hope this helps
   others gain some clarification also. I’m sorry to hear that Patchstack are being
   so unresponsive.
 * Kind regards,
 *  Plugin Author [Ideal Postcodes](https://wordpress.org/support/users/idealpostcodes/)
 * (@idealpostcodes)
 * [9 months, 2 weeks ago](https://wordpress.org/support/topic/unpatch-security-issue/#post-18692708)
 * Thanks for your understanding. We’re keeping an overview and timeline to resolution
   here: [https://docs.ideal-postcodes.co.uk/docs/integrations/woocommerce#cve-2025-57923-sensitive-data-exposure-report](https://docs.ideal-postcodes.co.uk/docs/integrations/woocommerce#cve-2025-57923-sensitive-data-exposure-report)
 *  Plugin Author [Ideal Postcodes](https://wordpress.org/support/users/idealpostcodes/)
 * (@idealpostcodes)
 * [8 months, 4 weeks ago](https://wordpress.org/support/topic/unpatch-security-issue/#post-18718140)
 * Hi there
 * We were able to get a hold of PatchStack a couple weeks ago to close this off:
   [https://patchstack.com/database/wordpress/plugin/uk-address-postcode-validation/vulnerability/wordpress-uk-address-postcode-validation-plugin-3-9-2-sensitive-data-exposure-vulnerability](https://patchstack.com/database/wordpress/plugin/uk-address-postcode-validation/vulnerability/wordpress-uk-address-postcode-validation-plugin-3-9-2-sensitive-data-exposure-vulnerability)
 *  Thread Starter [ajreading](https://wordpress.org/support/users/ajreading/)
 * (@ajreading)
 * [8 months, 4 weeks ago](https://wordpress.org/support/topic/unpatch-security-issue/#post-18718387)
 * Thank you. We’re up to date and the warnings have cleared.
 * Thanks again for your detailed response and follow up.

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘Unpatch Security Issue’ is closed to new replies.

 * ![](https://ps.w.org/uk-address-postcode-validation/assets/icon.svg?rev=3260911)
 * [UK Address Postcode Validation](https://wordpress.org/plugins/uk-address-postcode-validation/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/uk-address-postcode-validation/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/uk-address-postcode-validation/)
 * [Active Topics](https://wordpress.org/support/plugin/uk-address-postcode-validation/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/uk-address-postcode-validation/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/uk-address-postcode-validation/reviews/)

 * 7 replies
 * 2 participants
 * Last reply from: [ajreading](https://wordpress.org/support/users/ajreading/)
 * Last activity: [8 months, 4 weeks ago](https://wordpress.org/support/topic/unpatch-security-issue/#post-18718387)
 * Status: resolved