Exposure of Private Personal Information to an Unauthorized Actor Affecting universal-omega/dynamic-page-list3 package, versions <3.6.4


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.06% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-UNIVERSALOMEGADYNAMICPAGELIST3-10734110
  • published14 Jul 2025
  • disclosed10 Jul 2025
  • creditMarkus-Rost

Introduced: 10 Jul 2025

NewCVE-2025-53625  (opens in a new tab)
CWE-359  (opens in a new tab)

How to fix?

Upgrade universal-omega/dynamic-page-list3 to version 3.6.4 or higher.

Overview

universal-omega/dynamic-page-list3 is a The DynamicPageList3 extension allows creating lists of other articles based on their category, namespace, title, references or template usage and include contents or arguments of template calls of those articles into your page.

Affected versions of this package are vulnerable to Exposure of Private Personal Information to an Unauthorized Actor via the #dpl parameters. An attacker can access hidden or suppressed usernames by crafting specific queries that exploit the exposure of sensitive user information.

References

CVSS Base Scores

version 4.0
version 3.1