cleantalk
Vulnerabilities and Security Researches

PPWP – Password Protect Pages, CVE-2024-0620

CVE, Research URL

CVE-2024-0620

Published on
Feb 29, 2024
Research Description
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. This makes it possible for unauthenticated attackers to obtain post titles, IDs, slugs as well as other information including for password-protected posts.
Affected versions
Min -, max 1.9.0.
Status
vulnerable