PT-2025-27894 · Unknown · Sharable Password Protected Posts

Pierre Rudloff

·

Published

2025-07-04

·

Updated

2025-07-09

·

CVE-2025-5920

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Sharable Password Protected Posts version 1.1.1 and earlier
Description: The issue allows access to password protected posts by providing a secret key in a GET parameter. However, the key is exposed by the REST API.
Recommendations: For versions prior to 1.1.1, update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API to minimize the risk of exploitation. Avoid using the secret key in GET parameters until the issue is resolved.

Exploit

Fix

Related Identifiers

CVE-2025-5920

Affected Products

Sharable Password Protected Posts