Impact
The Wp Edit Password Protected WordPress plugin before version 1.3.5 implements a mechanism intended to protect page content with a password. However, the protection can be bypassed by sending specially crafted requests to the plugin’s REST API. The flaw allows an attacker to retrieve protected content without knowing the correct password, bypassing the intended access control. It is a weakness of the type insecure authorization, as identified by CWE-863.
Affected Systems
This issue affects WordPress sites that use the Wp Edit Password Protected plugin, specifically any installations on versions prior to 1.3.5. The plugin’s vendor information is not explicitly listed; it is a third‑party WordPress plugin. Users should verify the plugin version in their wp-content/plugins directory and consider disabling or removing the plugin if the vulnerable version cannot be updated.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate severity. EPSS information is not available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker who can make REST API calls to the WordPress site can exploit this flaw, potentially exposing sensitive page content.
OpenCVE Enrichment