Wpexpertdeveloper
Wpexpertdeveloper WP Private Content Plus: vulnerabilidades y CVE
Wpexpertdeveloper WP Private Content Plus tiene 6 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-10720 | Media (6.5) | 0.30% | — | 13 oct 2025 | The WP Private Content Plus through 3.6.2 provides a global content protection feature that requires a password. However, the access control check is based only on the presence of an unprotected client-side cookie. As a… |
| CVE-2025-4390 | Media (5.3) | 0.33% | — | 12 ago 2025 | The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validate_restrictions' function. This makes it possible for… |
| CVE-2024-11292 | Media (5.3) | 0.45% | — | 6 dic 2024 | The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.1 via the WordPress core search feature. This makes it possible for… |
| CVE-2024-0680 | Media (5.3) | 0.60% | — | 28 feb 2024 | The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 3.6. This is due to the plugin not properly restricting access to posts via the REST API… |
| CVE-2021-4385 | Media (4.3) | 0.38% | — | 1 jul 2023 | The WP Private Content Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1. This is due to missing or incorrect nonce validation on the save_groups() function.… |
| CVE-2019-15816 | Alta (7.5) | 2.0% | — | 30 ago 2019 | The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via save_settings_page and other save_ functions. |