The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 3.6. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected posts.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | WP Private Content Plus <= 3.6 - Protection Mechanism Bypass | |
| Weaknesses | CWE-693 | |
| References |
|
Fri, 07 Feb 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpexpertdeveloper
Wpexpertdeveloper wp Private Content Plus |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:wpexpertdeveloper:wp_private_content_plus:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpexpertdeveloper
Wpexpertdeveloper wp Private Content Plus |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:49:15.186Z
Reserved: 2024-01-18T13:47:43.912Z
Link: CVE-2024-0680
Updated: 2024-08-01T18:11:35.683Z
Status : Modified
Published: 2024-02-28T09:15:41.403
Modified: 2026-04-08T18:18:56.167
Link: CVE-2024-0680
No data.
OpenCVE Enrichment
No data.