CVE-2025-10720 - WP Private Content Plus <= 3.6.2 - Password Protection Bypass
CVE ID : CVE-2025-10720
Published : Oct. 13, 2025, 10:15 a.m. | 1 hour, 54 minutes ago
Description : The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 13, 2025, 10:15 a.m. | 1 hour, 54 minutes ago
Description : The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...