Home

Description

The DocCheck Login plugin for WordPress is vulnerable to unauthorized post access in all versions up to, and including, 1.1.5. This is due to plugin redirecting a user to login on a password protected post after the page has loaded. This makes it possible for unauthenticated attackers to read posts they should not have access to.

PUBLISHED Reserved 2025-06-27 | Published 2025-07-04 | Updated 2025-07-08 | Assigner Wordfence




MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-284 Improper Access Control

Product status

Default status
unaffected

* (semver)
affected

Timeline

2025-07-03:Disclosed

Credits

Jonas Benjamin Friedli finder

References

www.wordfence.com/...-b1c4-4451-97c1-f8d5ed26a2d5?source=cve

wordpress.org/plugins/doccheck-login/

cve.org (CVE-2025-6786)

nvd.nist.gov (CVE-2025-6786)

Download JSON