The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 3.6. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected posts.
History

Fri, 07 Feb 2025 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Wpexpertdeveloper
Wpexpertdeveloper wp Private Content Plus
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:wpexpertdeveloper:wp_private_content_plus:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpexpertdeveloper
Wpexpertdeveloper wp Private Content Plus

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-02-28T08:33:06.596Z

Updated: 2024-08-01T18:11:35.683Z

Reserved: 2024-01-18T13:47:43.912Z

Link: CVE-2024-0680

cve-icon Vulnrichment

Updated: 2024-08-01T18:11:35.683Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-28T09:15:41.403

Modified: 2025-02-07T01:27:25.297

Link: CVE-2024-0680

cve-icon Redhat

No data.