The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 3.6. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected posts.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Feb 2025 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpexpertdeveloper
Wpexpertdeveloper wp Private Content Plus |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:wpexpertdeveloper:wp_private_content_plus:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpexpertdeveloper
Wpexpertdeveloper wp Private Content Plus |

Status: PUBLISHED
Assigner: Wordfence
Published: 2024-02-28T08:33:06.596Z
Updated: 2024-08-01T18:11:35.683Z
Reserved: 2024-01-18T13:47:43.912Z
Link: CVE-2024-0680

Updated: 2024-08-01T18:11:35.683Z

Status : Analyzed
Published: 2024-02-28T09:15:41.403
Modified: 2025-02-07T01:27:25.297
Link: CVE-2024-0680

No data.