Security Advisory

CVE-2025-10720

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-10-13 09:37:14
Last updated 2025-10-28 20:35:31
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a result, an unauthenticated attacker can completely bypass the password protection by manually setting the cookie value in their browser.