PT-2025-17883 · WordPress · Prevent Direct Access – Protect Wordpress Files

Tom Broucke

·

Published

2025-04-25

·

Updated

2025-04-25

·

CVE-2025-3923

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Prevent Direct Access – Protect WordPress Files plugin versions up to, and including, 2.8.8
Description The issue allows unauthenticated attackers to extract sensitive data, including files protected by the plugin, due to insufficient randomness of the generated file name via the generate unique string. This makes it possible for attackers to determine the file name and access protected files.
Recommendations For versions up to, and including, 2.8.8, consider disabling the generate unique string function until a patch is available to prevent predictable file names. Restrict access to sensitive files protected by the plugin to minimize the risk of exploitation. Avoid using the plugin until a newer version with improved randomness for generated file names is released.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-3923

Affected Products

Prevent Direct Access – Protect Wordpress Files