CVE-2025-26966

WordPress PrivateContent plugin <= 8.11.5 - Unauthenticated Account Takeover vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in Aldo Latino PrivateContent. This issue affects PrivateContent: from n/a through 8.11.5.


We have discovered 1,117 live websites that are affected by CVE-2025-26966.

Run a Free Instant Scan




Affected Software

Product  Private Content
Category Wordpress Plugins
Vulnerable Domains1,117 live websites (100% of Private Content install base)
Vulnerable Versions
  • from 0 through 8.11.5
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-288 Authentication Bypass Using an Alternate Path or Channel



Details

  • Published - Feb 25, 2025
  • Updated - Feb 25, 2025

Credits

  • Rafie Muhammad (Patchstack) (finder)

Website Distribution by Country

Number of websites using CVE-2025-26966
United States182 websites



Italy293 websites
Spain105 websites
France103 websites
Germany70 websites
GB60 websites
Brazil56 websites
Netherlands31 websites
Portugal22 websites
Canada16 websites

Website Distribution by TLD

Number of websites using CVE-2025-26966
.com360 websites
.it232 websites
.org74 websites
.com.br44 websites
.es39 websites
.eu32 websites
.net27 websites
.fr26 websites
.nl24 websites
.co.uk23 websites

Websites affected by CVE-2025-26966

Top websites that are affected by CVE-2025-26966. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.**.uk GB***,***
******.com Spain***,***
********************.it Italy***,***
*************************.org GB***,***
**********************.com GB***,***
************.eu Belgium***,***
*********.org Netherlands***,***
*************.org South Africa***,***
***.***.uk GB***,***
****.***.pl Poland***,***
See full domain list

FAQ

CVE-2025-26966 is Authentication Bypass Using an Alternate Path or Channel in Private Content
A total of 1,117 websites have been identified as vulnerable to CVE-2025-26966, based on global website indexing conducted by WebTechSurvey.
The Private Content is affected by the CVE-2025-26966 vulnerability.
Private Content versions up to and including 8.11.5 are vulnerable to CVE-2025-26966.