The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 3.6. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected posts.
History

Wed, 08 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 17:45:00 +0000

Type Values Removed Values Added
Title WP Private Content Plus <= 3.6 - Protection Mechanism Bypass
Weaknesses CWE-693
References

Fri, 07 Feb 2025 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Wpexpertdeveloper
Wpexpertdeveloper wp Private Content Plus
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:wpexpertdeveloper:wp_private_content_plus:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpexpertdeveloper
Wpexpertdeveloper wp Private Content Plus

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:49:15.186Z

Reserved: 2024-01-18T13:47:43.912Z

Link: CVE-2024-0680

cve-icon Vulnrichment

Updated: 2024-08-01T18:11:35.683Z

cve-icon NVD

Status : Modified

Published: 2024-02-28T09:15:41.403

Modified: 2026-04-08T18:18:56.167

Link: CVE-2024-0680

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.