Логотип exploitDog
bind:CVE-2025-10720
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-10720

Количество 2

Количество 2

nvd логотип

CVE-2025-10720

4 месяца назад

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gc32-f5qg-q57v

4 месяца назад

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-10720

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-gc32-f5qg-q57v

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.

CVSS3: 6.5
0%
Низкий
4 месяца назад

Уязвимостей на страницу