Medium severity5.3NVD Advisory· Published Aug 12, 2025· Updated Apr 15, 2026
CVE-2025-4390
CVE-2025-4390
Description
The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.2 via the 'validate_restrictions' function. This makes it possible for unauthenticated attackers to extract sensitive data including the content of resticted posts on archive and feed pages.
Affected products
1- Range: <=3.6.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- plugins.trac.wordpress.org/browser/wp-private-content-plus/trunk/classes/class-wppcp-private-posts-pages.phpnvd
- plugins.trac.wordpress.org/browser/wp-private-content-plus/trunk/classes/class-wppcp-private-posts-pages.phpnvd
- www.wordfence.com/threat-intel/vulnerabilities/id/4c305546-1548-4b77-a484-d7c51d829792nvd
News mentions
0No linked articles in our index yet.