Vulnerability Description
The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.
CVSS Score
MEDIUM
References
FAQ
What is CVE-2025-10720?
CVE-2025-10720 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected clien...
How severe is CVE-2025-10720?
CVE-2025-10720 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-10720?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.