Pending AI Enrichment

This vulnerability was recently detected via the live feed and has not yet been processed by Precogs AI's context enrichment engine. The data below represents raw telemetric data.

RAW NVD TELEMETRY

CVE-2025-11729

CVSS Base Score
4.3 MEDIUM
Primary Weakness
CWE-285
Published Date
Aug 19, 2026
Data Source
NVD API

The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the can_access function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Contributor-level access and above, to retrieve a master-password and access any password-protected content.

Related Vulnerabilitiesvia CWE-285

CVE-2026-3310510 CRITICAL

Improper Authorization in Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network

CWE-285CWE-863
CVE-2026-340515.4 MEDIUM

Broken Access Control in OpenEMR Import/Export functionality before 8.0.0.3. Unauthorized users can perform direct requests to trigger data extraction and manipulation despite UI restrictions.

CWE-285
CVE-2026-340567.7 HIGH

Broken Access Control in OpenEMR up to 8.0.0.3 allows low-privilege users to view and download eRx error logs. This flaw compromises confidentiality by exposing sensitive patient information.

CWE-285
CVE-2026-331869.1 CRITICAL

gRPC-Go is the Go language implementation of gRPC.

CWE-285
CVE-2026-318368.1 HIGH

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations.

CWE-269CWE-285
CVE-2026-318690 UNKNOWN

Discourse is an open-source discussion platform.

CWE-200CWE-285CWE-639

Is your system affected?

Precogs AI detects CVE-2025-11729 in compiled binaries, LLMs, and application layers — even without source code access.