All 5 CVE vulnerabilities found in PrivateContent, with AI-generated Chinese analysis, references, and POCs.
Vendor: LCWeb
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-26976 | WordPress PrivateContent plugin <= 8.11.4 - SQL Injection vulnerability CWE-89 | 9.1 | - | 2025-03-15 |
| CVE-2025-26972 | WordPress PrivateContent plugin <= 8.11.5 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 | 7.1 | High | 2025-03-15 |
| CVE-2025-26969 | WordPress PrivateContent plugin <= 8.11.5 - Subscriber+ Site Wide Broken Access Control vulnerability CWE-862 | 8.3 | High | 2025-03-15 |
| CVE-2025-26966 | WordPress PrivateContent plugin <= 8.11.5 - Unauthenticated Account Takeover vulnerability CWE-288 | 7.5 | - | 2025-02-25 |
| CVE-2023-0581 | PrivateContent <= 8.4.3 - Protection Mechanism Bypass CWE-602 | 5.3 | Medium | 2023-01-30 |
All 5 known CVE vulnerabilities affecting PrivateContent with full Chinese analysis, references, and POCs where available.