CVE-2024-0620

MEDIUM

PPWP - WordPress <1.8.9 - Info Disclosure

Title source: llm
STIX 2.1

Description

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. This makes it possible for unauthenticated attackers to obtain post titles, IDs, slugs as well as other information including for password-protected posts.

Scores

CVSS v3 5.3
EPSS 0.0049
EPSS Percentile 38.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
buildwps/PPWP – Password Protect Pages < 1.8.9
passwordprotectwp/password_protect_wordpress < 1.9.0
Published Feb 29, 2024
Tracked Since Feb 18, 2026