Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-10720

Опубликовано: 13 окт. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.

EPSS

Процентиль: 33%
0.00134
Низкий

6.5 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 6.5
github
4 месяца назад

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.

EPSS

Процентиль: 33%
0.00134
Низкий

6.5 Medium

CVSS3

Дефекты