WP Private Content Plus Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability allowing sensitive information exposure has been identified in the WP Private Content Plus plugin for WordPress, affecting all versions through 3.6.2. The issue arises in the 'validate_restrictions' function, where unauthenticated attackers can access restricted post content on archive and feed pages.

Impact

Exploitation of this vulnerability allows unauthenticated users to access and extract sensitive information, specifically the content of restricted posts, from archive and feed pages.

Reproduction

The vulnerability can be reproduced by accessing an archive or feed page on a WordPress site with the WP Private Content Plus plugin version 3.6.2 or earlier. Unauthenticated users can then view restricted post content that should otherwise be protected.

Remediation

No known patch is available. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.

Added: Aug 12, 2025, 3:28 AM
Updated: Aug 12, 2025, 3:28 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.4
remediation
0.0
relevance
0.3
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.