The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.
History

Mon, 13 Oct 2025 09:45:00 +0000

Type Values Removed Values Added
Description The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.
Title WP Private Content Plus <= 3.6.2 - Password Protection Bypass
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-10-13T09:37:14.409Z

Reserved: 2025-09-19T10:32:37.291Z

Link: CVE-2025-10720

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-13T10:15:45.590

Modified: 2025-10-13T10:15:45.590

Link: CVE-2025-10720

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.