Unauthorized Access Weakness in Prevent Direct Access β Protect WordPress Files by WordPress
CVE-2025-3861
5.4MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 25 April 2025
Summary
The Prevent Direct Access β Protect WordPress Files plugin experiences a significant vulnerability due to a misconfigured capability check in the 'pda_lite_custom_permission_check' function. This flaw, present in versions 2.8.6 to 2.8.8.2, allows authenticated users with Contributor-level permissions or higher to bypass intended restrictions, leading to unauthorized access and modification of media protection statuses. This can compromise the integrity of protected files, posing a potential risk to site security.
Affected Version(s)
Prevent Direct Access β Protect WordPress Files 2.8.6 <= 2.8.8.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mattia Brollo