SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2025-11729

MEDIUM · CVSS 4.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable due to an improper capability check in the can_access function, allowing authenticated attackers with Contributor-level access or higher to retrieve the master password and gain unauthorized access to password-protected content. This vulnerability poses a medium risk as it can lead to data exposure of sensitive information. WordPress site administrators using this plugin should prioritize applying updates to mitigate potential exploitation.

CVE
CVE-2025-11729
Severity
MEDIUM
CVSS
4.3
EPSS
0.21%
WordPress

Original NVD Description

The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the can_access function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Contributor-level access and above, to retrieve a master-password and access any password-protected content.