CVE-2025-11729Medium· 4.3▾ SunlitThe PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the can_access function in all versions up to, and including, 1.9.1…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the can_access function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Contributor-level access and above, to retrieve a master-password and access any password-protected content.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-0017High· 7.7In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code
CVE-2026-102293High· 7.3A vulnerability was identified in realjerrytang tacomall 1.0.0
CVE-2026-102261Medium· 5.4A flaw has been found in owen2345 Camaleon CMS up to 2.9.2
CVE-2026-101006Medium· 4.3A flaw has been found in Frappe HR up to 16.15.0
CVE-2026-100897Medium· 5.5A security vulnerability has been detected in fuzui StudentInfo up to fcc42a639ec7cef620651bfd0f07ebb660529e3f
CVE-2026-100885High· 7.3A vulnerability was found in Krayin laravel-crm up to 2.2.4