CVE-2025-4390 – WordPress Private Content Plus Sensitive Information Exposure

CVE ID : CVE-2025-4390

Published : Aug. 12, 2025, 3:15 a.m. | 1 hour, 55 minutes ago

Description : The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the ‘validate_restrictions’ function. This makes it possible for unauthenticated attackers to extract sensitive data including the content of resticted posts on archive and feed pages.

Severity: 5.3 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Share the Post:

Related Posts