Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gc32-f5qg-q57v

Опубликовано: 13 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.

EPSS

Процентиль: 34%
0.00134
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
4 месяца назад

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.

EPSS

Процентиль: 34%
0.00134
Низкий

6.5 Medium

CVSS3