Vulnerability Description
The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.7 via the 'password_protected_cookie' function. This makes it possible for unauthenticated attackers to extract sensitive data including all protected site content if the 'Use Transient' setting is enabled.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/password-protected/trunk/includes/com
- https://plugins.trac.wordpress.org/changeset/3274358/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/241d75ca-55e3-461a-984
FAQ
What is CVE-2025-3453?
CVE-2025-3453 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and more plugin for WordPress is vulnerable to Sensitive I...
How severe is CVE-2025-3453?
CVE-2025-3453 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-3453?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.