The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secret key in a GET parameter. However, the key is exposed by the REST API.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-19963 The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secret key in a GET parameter. However, the key is exposed by the REST API.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 08 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Jul 2025 10:00:00 +0000

Type Values Removed Values Added
Description The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secret key in a GET parameter. However, the key is exposed by the REST API.
Title Sharable Password Protected Posts < 1.1.1 - Unauthenticated Password Protect Post Access
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-07-08T17:38:34.095Z

Reserved: 2025-06-09T13:28:28.737Z

Link: CVE-2025-5920

cve-icon Vulnrichment

Updated: 2025-07-07T19:45:40.618Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-04T10:15:24.223

Modified: 2025-07-08T18:15:42.893

Link: CVE-2025-5920

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.