← WordPress Vulnerabilities
WordPress security by component

Prevent Direct Access – Protect WordPress Files

Prevent Direct Access – Protect WordPress Files is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Apr 25, 2025; the highest CVE/CNA score is 5.4.

Plugin slug: prevent-direct-access

CVE-2025-3923: Prevent Direct Access – Protect WordPress Files: Sensitive information exposure

Prevent Direct Access – Protect WordPress Files is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.

PublishedApr 25, 2025
Safe version guidanceSee mitigation notes
Safe version
Apr 25, 2025 CVE-2025-3923
Prevent Direct Access – Protect WordPress Files: Sensitive information exposure
Prevent Direct Access – Protect WordPress Files is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Apr 25, 2025 CVE-2025-3861
Prevent Direct Access – Protect WordPress Files: A security weakness
Prevent Direct Access – Protect WordPress Files is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending