Information Exposure Vulnerability in Post Lockdown Plugin for WordPress
CVE-2025-1504
6.5MEDIUM
What is CVE-2025-1504?
The Post Lockdown plugin for WordPress contains a vulnerability that allows authenticated attackers with Subscriber-level access and higher to exploit the 'pl_autocomplete' AJAX action. Due to inadequate restrictions on the posts accessed through this action, it is possible for these users to retrieve sensitive data from password-protected, private, or draft posts without proper authorization, posing serious security risks for WordPress sites using this plugin.
Affected Version(s)
Post Lockdown * <= 4.0.2