PT-2025-27894 · Unknown · Sharable Password Protected Posts
Pierre Rudloff
·
Published
2025-07-04
·
Updated
2025-07-09
·
CVE-2025-5920
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Sharable Password Protected Posts version 1.1.1 and earlier
Description:
The issue allows access to password protected posts by providing a secret key in a
GET parameter. However, the key is exposed by the REST API.Recommendations:
For versions prior to 1.1.1, update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST
API to minimize the risk of exploitation. Avoid using the secret key in GET parameters until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sharable Password Protected Posts