Unauthorized Access Weakness in Prevent Direct Access β Protect WordPress Files by WordPress
CVE-2025-3861
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 April 2025
What is CVE-2025-3861?
The Prevent Direct Access β Protect WordPress Files plugin experiences a significant vulnerability due to a misconfigured capability check in the 'pda_lite_custom_permission_check' function. This flaw, present in versions 2.8.6 to 2.8.8.2, allows authenticated users with Contributor-level permissions or higher to bypass intended restrictions, leading to unauthorized access and modification of media protection statuses. This can compromise the integrity of protected files, posing a potential risk to site security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Prevent Direct Access β Protect WordPress Files 2.8.6 <= 2.8.8.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved