The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 13 Oct 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser. | |
Title | WP Private Content Plus <= 3.6.2 - Password Protection Bypass | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-10-13T09:37:14.409Z
Reserved: 2025-09-19T10:32:37.291Z
Link: CVE-2025-10720

No data.

Status : Received
Published: 2025-10-13T10:15:45.590
Modified: 2025-10-13T10:15:45.590
Link: CVE-2025-10720

No data.

No data.