WordPress Plugin Vulnerabilities

Sharable Password Protected Posts < 1.1.1 - Unauthenticated Password Protect Post Access

Description

The plugin allows access to password protected posts by providing a secret key in a GET parameter. However, the key is exposed by the REST API.

Proof of Concept

Affects Plugins

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
Pierre Rudloff
Submitter
Pierre Rudloff
Verified
Yes

Timeline

Publicly Published
2025-06-13 (about 6 months ago)
Added
2025-06-13 (about 6 months ago)
Last Updated
2025-07-04 (about 5 months ago)

Other