The PrivateContent plugin for WordPress is vulnerable to protection mechanism bypass due to the use of client side validation in versions up to, and including, 8.4.3. This is due to the plugin checking if an IP had been blocklist via client-side scripts rather than server-side. This makes it possible for unauthenticated attackers to bypass any login restrictions that may prevent a brute force attack.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2023-01-30T14:06:27.936Z
Updated: 2024-08-02T05:17:49.970Z
Reserved: 2023-01-30T14:06:16.652Z
Link: CVE-2023-0581
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-01-30T15:15:09.823
Modified: 2023-11-07T04:00:52.963
Link: CVE-2023-0581
Redhat
No data.