Private Content <= 9.9.2 - Unauthenticated Privilege Escalation
critical
The Private Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.9.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
- CVSS:
- 9.8
- Affected:
- up to 9.9.2
- Fixed in:
- 9.10.0
- Disclosed:
- Jul 1, 2026
CVE-2026-57692 on NVD →
Private Content [private-content] <= 8.11.5 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.
- Affected:
- up to 8.11.5
- Fix:
- No patched version reported
- Disclosed:
- Mar 15, 2025
CVE-2025-26969 on NVD →
Private Content [private-content] <= 8.11.4 (unfixed + closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8.11.4.
- Affected:
- up to 8.11.4
- Fix:
- No patched version reported
- Disclosed:
- Mar 15, 2025
CVE-2025-26976 on NVD →
Private Content [private-content] <= 8.11.5 (unfixed + closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.
- Affected:
- up to 8.11.5
- Fix:
- No patched version reported
- Disclosed:
- Mar 15, 2025
CVE-2025-26972 on NVD →
Private Content [private-content] <= 8.11.5 (unfixed + closed)
unknown
[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.
- Affected:
- up to 8.11.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 25, 2025
CVE-2025-26966 on NVD →
Private Content <= 8.11.5 - Unauthenticated Privilege Escalation via Account Takeover
critical
The Private Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.11.5. This makes it possible for unauthenticated attackers to takeover other user's accounts effectively elevating their privileges.
- CVSS:
- 9.8
- Affected:
- up to 8.11.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 24, 2025
CVE-2025-26966 on NVD →
Private Content <= 8.11.5 - Authenticated (Subscriber+) SQL Injection
medium
The Private Content plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 8.11.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access...
- CVSS:
- 6.5
- Affected:
- up to 8.11.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 24, 2025
CVE-2025-26976 on NVD →
Private Content <= 8.11.5 - Reflected Cross-Site Scripting
medium
The Private Content plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 8.11.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...
- CVSS:
- 6.1
- Affected:
- up to 8.11.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 24, 2025
CVE-2025-26972 on NVD →
Private Content <= 8.11.5 - Missing Authorization
medium
The Private Content plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in all versions up to, and including, 8.11.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 5.4
- Affected:
- up to 8.11.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 24, 2025
CVE-2025-26969 on NVD →
PrivateContent <= 8.4.3 - Protection Mechanism Bypass
medium
The PrivateContent plugin for WordPress is vulnerable to protection mechanism bypass due to the use of client side validation in versions up to, and including, 8.4.3. This is due to the plugin checking if an IP had been blocklist via client-side scripts rather than server-side. This makes it possible for unauthenticate...
- CVSS:
- 5.3
- Affected:
- up to 8.4.3
- Fixed in:
- 8.4.4
- Disclosed:
- Jan 30, 2023
CVE-2023-0581 on NVD →
Private Content [private-content] < 8.4.4 (closed)
unknown
[en] The PrivateContent plugin for WordPress is vulnerable to protection mechanism bypass due to the use of client side validation in versions up to, and including, 8.4.3. This is due to the plugin checking if an IP had been blocklist via client-side scripts rather than server-side. This makes it possible for unauthent...
- Affected:
- up to 8.4.4
- Fixed in:
- 8.4.4
- Disclosed:
- Jan 30, 2023
CVE-2023-0581 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database