Sensitive Information Exposure Vulnerability in Prevent Direct Access Plugin by WordPress
CVE-2025-3923
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 April 2025
What is CVE-2025-3923?
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is susceptible to exposure of sensitive data due to insufficient randomness in the generated file names. Unauthenticated attackers can exploit this vulnerability to access and extract protected files if they can deduce the file name, posing potential risks to sensitive information stored by the plugin.
Affected Version(s)
Prevent Direct Access – Protect WordPress Files * <= 2.8.8