The PrivateContent plugin for WordPress is vulnerable to protection mechanism bypass due to the use of client side validation in versions up to, and including, 8.4.3. This is due to the plugin checking if an IP had been blocklist via client-side scripts rather than server-side. This makes it possible for unauthenticated attackers to bypass any login restrictions that may prevent a brute force attack.
Metrics
Affected Vendors & Products
References
History
Mon, 13 Jan 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-01-13T17:09:35.434Z
Reserved: 2023-01-30T14:06:16.652Z
Link: CVE-2023-0581

Updated: 2024-08-02T05:17:49.970Z

Status : Modified
Published: 2023-01-30T15:15:09.823
Modified: 2024-11-21T07:37:26.240
Link: CVE-2023-0581

No data.