CVE-2025-10720 affects WP Private Content Plus through version 3.6.2. The plugin's global content protection feature is intended to restrict access to protected content behind a password prompt. However, the protection decision is enforced solely by checking for the presence of a client-side cookie that is not itself protected or cryptographically validated. Because the access control logic trusts client-controlled state, an unauthenticated attacker can bypass the password gate by manually creating or modifying the expected cookie value in the browser, gaining access to content that should require prior password verification.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) for CVE-2025-10720, an authentication bypass vulnerability in the WordPress plugin WP Private Content Plus v3.6.2. The vulnerability arises from the plugin's reliance on a client-side cookie ('wppcp_global_password_protected_status') to determine access to password-protected content. By manually setting this cookie to 'ACTIVE' in the browser, any unauthenticated user can bypass the password protection. The PoC demonstrates this by instructing the user to set the cookie via JavaScript in the browser console. The repository consists of two markdown files: 'PoC.md', which details the vulnerability, exploitation steps, and technical analysis (including a code snippet from the vulnerable plugin), and 'README.md', which summarizes the issue and provides references. No automated exploit script is provided; the exploit is performed manually via browser developer tools.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.