What is CVE-2025-10005?
This vulnerability affects the PPWP – Password Protect WordPress plugin in all versions up to and including 1.9.20. Due to missing validation on a user-controlled key in the 'ppw_free_set_password' AJAX action, an unauthenticated attacker can modify passwords via an Insecure Direct Object Reference (IDOR) flaw. It is recommended to temporarily deactivate the plugin until an update is released by the developer.
Azərbaycanca: Bu boşluq, PPWP (Password Protect WordPress) plagininin 1.9.20 daxil olmaqla bütün versiyalarını təsir edir. 'ppw_free_set_password' AJAX funksiyasında istifadəçi tərəfindən idarə olunan açarda yoxlamanın olmaması səbəbindən, autentifikasiya olunmamış hücumçu Insecure Direct Object Reference (IDOR) vasitəsilə parolları dəyişdirə bilər. Plaginin tərtibatçısı tərəfindən yeniləmə yayımlanana qədər plaqini müvəqqəti olaraq deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of the PPWP plugin are affected by CVE-2025-10005?
The vulnerability affects all versions of the PPWP – Password Protect WordPress plugin up to and including 1.9.20.
What method can an attacker use to change passwords via CVE-2025-10005?
An unauthenticated attacker can modify passwords via an Insecure Direct Object Reference (IDOR) flaw due to missing validation on a user-controlled key in the 'ppw_free_set_password' AJAX action.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.