The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secret key in a GET parameter. However, the key is exposed by the REST API.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-19963 The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secret key in a GET parameter. However, the key is exposed by the REST API.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 13 Jan 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Fabiantodt
Fabiantodt private Post Share
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:fabiantodt:private_post_share:*:*:*:*:*:wordpress:*:*
Vendors & Products Fabiantodt
Fabiantodt private Post Share

Tue, 08 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Jul 2025 10:00:00 +0000

Type Values Removed Values Added
Description The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secret key in a GET parameter. However, the key is exposed by the REST API.
Title Sharable Password Protected Posts < 1.1.1 - Unauthenticated Password Protect Post Access
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-07-08T17:38:34.095Z

Reserved: 2025-06-09T13:28:28.737Z

Link: CVE-2025-5920

cve-icon Vulnrichment

Updated: 2025-07-07T19:45:40.618Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-04T10:15:24.223

Modified: 2026-01-13T21:49:45.850

Link: CVE-2025-5920

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses