WP Private Content Plus Password Protection Bypass Vulnerability

Vulnerability

A vulnerability in the WP Private Content Plus plugin, affecting versions through 3.6.2, allows unauthenticated attackers to bypass global password protection. The vulnerability arises because the access control relies solely on an unprotected client-side cookie. Attackers can manually set the cookie value in their browser to gain access to protected content.

Impact

Exploitation of this vulnerability allows for unauthorized access to content that is meant to be password protected.

Reproduction

To reproduce this vulnerability, first enable the private content module in the WP Private Content Plus plugin settings. Then, navigate to the password settings tab, enable global password protection for all users, set a password, and save the changes. Afterward, go to a page that is protected by the password, which will prompt for the password entry. Open the browser's developer tools, create a new cookie by setting the 'wppcp_global_password_protected_status' to 'ACTIVE', and refresh the page to bypass the password protection.

Added: Oct 13, 2025, 10:19 AM
Updated: Oct 13, 2025, 10:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.7
remediation
0.0
relevance
0.7
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.