Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-4390

Опубликовано: 12 авг. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 5.3

Описание

The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validate_restrictions' function. This makes it possible for unauthenticated attackers to extract sensitive data including the content of resticted posts on archive and feed pages.

РелизСтатусПримечание
devel

not-affected

esm-apps/jammy

not-affected

esm-apps/noble

not-affected

esm-infra/focal

DNE

focal

DNE

jammy

not-affected

noble

not-affected

oracular

ignored

end of life, was needs-triage
plucky

not-affected

upstream

not-affected

Показывать по

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
6 месяцев назад

The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validate_restrictions' function. This makes it possible for unauthenticated attackers to extract sensitive data including the content of resticted posts on archive and feed pages.

CVSS3: 5.3
github
6 месяцев назад

The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validate_restrictions' function. This makes it possible for unauthenticated attackers to extract sensitive data including the content of resticted posts on archive and feed pages.

5.3 Medium

CVSS3