
Proof-of-concept exploit for an authentication bypass vulnerability (CWE-565) in WP Private Content Plus v3.6.2, allowing unauthenticated access to password-protected content via client-side cookie manipulation.
This proof of concept (PoC) describes an authentication bypass vulnerability found in the WordPress plugin WP Private Content Plus v3.6.2. The issue allows unauthenticated users to bypass password-protected content due to improper reliance on client-side cookies.
Successful exploitation allows unauthenticated users to access content protected by the plugin’s global password feature.