CVE-2025-4390: WP Private Content Plus <= 3.6.2 - Unauthenticated Sensitive Information Exposure
The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validaterestrictions' function. This makes it possible for unauthenticated attackers to extract sensitive data including the content of resticted posts on archive and feed pages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4390?
CVE-2025-4390 is classified as a high-severity vulnerability due to its potential to expose sensitive user data.
How do I fix CVE-2025-4390?
To fix CVE-2025-4390, update the WP Private Content Plus plugin to version 3.6.3 or later.
Who is affected by CVE-2025-4390?
Any user of the WP Private Content Plus plugin up to and including version 3.6.2 is affected by CVE-2025-4390.
What type of vulnerability is CVE-2025-4390?
CVE-2025-4390 is categorized as Sensitive Information Exposure.
Can unauthenticated attackers exploit CVE-2025-4390?
Yes, unauthenticated attackers can exploit CVE-2025-4390 to access sensitive data.