CVE Database
/

CVE-2025-10720

Back to search

CVE-2025-10720

Published: Oct 13, 2025

Modified: Oct 28, 2025

PUBLISHED

Description

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.

VendorProductVersions

Unknown

WP Private Content Plus

affected
0 - <= 3.6.2

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now