6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Description
The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.
Basic Information
ID
CVE-2025-10720
Source
WPScan
Published
Oct 13, 2025 at 09:37
Modified
Oct 28, 2025 at 20:35
Affected Product
Vendor
Unknown
Product
WP Private Content Plus
Affected Versions
Unknown WP Private Content Plus 0