CVE-2025-10720: WP Private Content Plus <= 3.6.2 - Password Protection Bypass
The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10720?
CVE-2025-10720 is considered a high severity vulnerability due to its potential for unauthenticated exploitation.
How do I fix CVE-2025-10720?
To fix CVE-2025-10720, update the WP Private Content Plus plugin to the latest version beyond 3.6.2.
What type of vulnerability is CVE-2025-10720?
CVE-2025-10720 is an access control vulnerability that allows attackers to bypass content protection.
Who is affected by CVE-2025-10720?
Users of the WP Private Content Plus plugin in versions up to and including 3.6.2 are affected by CVE-2025-10720.
Can CVE-2025-10720 be exploited remotely?
Yes, CVE-2025-10720 can be exploited remotely, as it allows unauthenticated attackers to bypass access controls.