MEDIUM 4.3 NVD
CVE-2025-11729
The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability
The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the can_access function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Contributor-level access and above, to retrieve a master-password and access any password-protected content.
References
- https://plugins.trac.wordpress.org/changeset/3486400/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d1e041f0-3019-4d1f-b1a3-b40275c0
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-08-19 via NVD.
vulnfeed aggregates 11955 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.