Unauthorized Data Access in PPWP Plugin for WordPress
CVE-2025-11729

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 August 2026

What is CVE-2025-11729?

The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress exhibits a serious vulnerability due to the lack of adequate capability checks in its can_access function. This flaw allows authenticated attackers, holding Contributor-level access and above, to bypass security measures and gain access to sensitive password-protected content, including the retrieval of the master password. All versions up to and including 1.9.15 are affected, which poses a significant risk to the privacy and security of user data.

Affected Version(s)

PPWP – Password Protect Pages 0 <= 1.9.15

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn (Jitlada)
.