The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 21 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nimeshrmr
Nimeshrmr wp Private Content Plus Wordpress Wordpress wordpress |
|
| Vendors & Products |
Nimeshrmr
Nimeshrmr wp Private Content Plus Wordpress Wordpress wordpress |
Mon, 13 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser. | |
| Title | WP Private Content Plus <= 3.6.2 - Password Protection Bypass | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2025-10-13T09:37:14.409Z
Updated: 2025-10-28T20:35:31.151Z
Reserved: 2025-09-19T10:32:37.291Z
Link: CVE-2025-10720
Updated: 2025-10-28T20:35:23.209Z
Status : Awaiting Analysis
Published: 2025-10-13T10:15:45.590
Modified: 2025-10-28T21:15:37.157
Link: CVE-2025-10720
No data.