What is CVE-2025-11729?
The PPWP: Password Protect Pages plugin for WordPress (up to version 1.9.15) has an unauthorized data access vulnerability due to an improper capability check in the 'can_access' function. This allows authenticated attackers with Contributor-level access to view protected content. It is recommended to immediately update the plugin to the latest version.
Azərbaycanca: WordPress üçün PPWP: Password Protect Pages plaqini (1.9.15-ə qədər) can_access funksiyasında düzgün olmayan icazə yoxlaması səbəbindən məlumatlara icazəsiz giriş zəifliyi mövcuddur. Bu, Contributor roluna malik autentifikasiya olunmuş hücumçulara qorunan səhifələri görməyə imkan verir. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which WordPress plugin is affected by CVE-2025-11729?
This vulnerability affects the PPWP: Password Protect Pages plugin up to version 1.9.15.
What level of access does an attacker need to exploit CVE-2025-11729, and what can they achieve?
An attacker must have authenticated access with a Contributor role. This vulnerability allows them to view protected content.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.