Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-10720-PoC — Proof-of-concept exploit for an authentication bypass vulnerability (CWE-565) in WP Private Content Plus v3.6.2, allowing unauthenticated access to password-protected content via client-side cookie manipulation. | Kitploit
Tools/GitHubGitHub/lorenzocamilli/cve-2025-10720-poc
Authentication & AuthorizationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHublorenzocamilli/cve-2025-10720-poc

CVE-2025-10720-PoC

Proof-of-concept exploit for an authentication bypass vulnerability (CWE-565) in WP Private Content Plus v3.6.2, allowing unauthenticated access to password-protected content via client-side cookie manipulation.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
43 months agoNot yet reviewed

Description

This proof of concept (PoC) describes an authentication bypass vulnerability found in the WordPress plugin WP Private Content Plus v3.6.2. The issue allows unauthenticated users to bypass password-protected content due to improper reliance on client-side cookies.

Details

  • Vulnerability Type: Authentication Bypass (Unauthenticated)
  • CWE-ID: CWE-565 - Reliance on Cookies without Validation and Integrity Checking

Impact

Successful exploitation allows unauthenticated users to access content protected by the plugin’s global password feature.

References

  • Video demo
  • WPScan
  • Affected plugin
Download Tool