CyberRota Analysis
AI-GeneratedThe PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable due to an improper capability check in the can_access function, allowing authenticated attackers with Contributor-level access or higher to retrieve the master password and gain unauthorized access to password-protected content. This vulnerability poses a medium risk as it can lead to data exposure of sensitive information. WordPress site administrators using this plugin should prioritize applying updates to mitigate potential exploitation.
Original NVD Description
The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the can_access function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Contributor-level access and above, to retrieve a master-password and access any password-protected content.