Impact
The Password Protect Pages plugin contains an improper authorization check on the can_access function, allowing authenticated users with the Contributor role or higher to retrieve the master password that protects all password‑protected content. This flaw is a classic authority bypass (CWE‑285) and enables the attacker to decrypt and view any protected content without additional privileges.
Affected Systems
The affected product is the BuildWPS PPWP – Password Protect Pages WordPress plugin. All versions up to and including 1.9.15 are vulnerable; newer releases have fixed the issue.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. No EPSS value is available, and the vulnerability is not listed in CISA’s KEV catalog. Because the attack requires only an authenticated Contributor‑level account, the risk depends on the number of users with that role. If such accounts can be compromised internally, the entire password‑protected content becomes accessible.
OpenCVE Enrichment