PT-2025-16952 · WordPress · Password Protect

Audrey François

+1

·

Publicado

2025-04-17

·

Atualizado

2025-04-19

·

CVE-2025-3453

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Password Protected plugin versions up to, and including, 2.7.7
Description The issue allows unauthenticated attackers to extract sensitive data, including all protected site content, if the 'Use Transient' setting is enabled. This is possible due to sensitive information exposure via the password protected cookie function.
Recommendations For Password Protected plugin versions up to, and including, 2.7.7, consider disabling the password protected cookie function until a patch is available. Additionally, disabling the 'Use Transient' setting may help minimize the risk of exploitation.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-3453

Produtos afetados

Password Protect