Password Protect WordPress Lite <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ppwp' shortcode in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it...
- CVSS:
- 6.4
- Affected:
- up to 1.9.21
- Fixed in:
- 1.9.22
- Disclosed:
- Aug 24, 2026
CVE-2025-9878 on NVD →
PPWP – Password Protect Pages <= 1.9.18 - Authenticated (Contributor+) PHP Object Injection via post_protection_roles
high
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This makes it possible for authenticated attackers, with Contributor-level access and ab...
- CVSS:
- 8.8
- Affected:
- up to 1.9.18
- Fixed in:
- 1.9.19
- Disclosed:
- Aug 22, 2026
CVE-2026-0551 on NVD →
PPWP: Password Protect Pages, Posts & Full or Partial Content <= 1.9.15 - Improper Authorization To Authenticated (Contributor+) Master Password Exposure
medium
The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the can_access function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Contributor-level acces...
- CVSS:
- 4.3
- Affected:
- up to 1.9.15
- Fixed in:
- 1.9.16
- Disclosed:
- Aug 18, 2026
CVE-2025-11729 on NVD →
Password Protect WordPress Lite <= 1.9.20 - Insecure Direct Object Reference to Authenticated (Contributor+) Password Protected Post Password Update
medium
The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.20 via the ppw_free_set_password AJAX action due to missing validation on a user controlled key. This makes it possible for authentica...
- CVSS:
- 4.3
- Affected:
- up to 1.9.20
- Fixed in:
- 1.9.21
- Disclosed:
- Aug 15, 2026
CVE-2025-10005 on NVD →
PPWP – Password Protect Pages <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
medium
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a...
- CVSS:
- 6.4
- Affected:
- up to 1.9.21
- Fixed in:
- 1.9.22
- Disclosed:
- Aug 12, 2026
CVE-2026-3639 on NVD →
PPWP – Password Protect Pages <= 1.9.19 - Authenticated (Contributor+) Insecure Direct Object Reference
medium
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.19 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorize...
- CVSS:
- 4.3
- Affected:
- up to 1.9.19
- Fixed in:
- 1.9.20
- Disclosed:
- Jun 26, 2026
CVE-2026-57634 on NVD →
PPWP – Password Protect Pages <= 1.9.15 - Missing Authorization
medium
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.9.15
- Fixed in:
- 1.9.16
- Disclosed:
- Mar 23, 2026
CVE-2026-32562 on NVD →
PPWP – Password Protect Pages <= 1.9.10 - Authenticated (Subscriber+) Content Exposure via REST API
medium
The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.10 due to insufficient protection on REST API endpoints when password protection is enabled. This makes it possible for unauthenticated...
- CVSS:
- 4.3
- Affected:
- up to 1.9.10
- Fixed in:
- 1.9.11
- Disclosed:
- Aug 25, 2025
CVE-2025-5998 on NVD →
PPWP – Password Protect Pages <= 1.9.5 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
medium
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level ro...
- CVSS:
- 5.3
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.6
- Disclosed:
- Dec 16, 2024
CVE-2024-11280 on NVD →
PPWP – Password Protect Pages <= 1.8.9 - Protection Mechanism Bypass
medium
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. This makes it possible for unauthenticated attackers to obtain post titles, IDs, slugs as well as other information including for password-protected posts.
- CVSS:
- 5.3
- Affected:
- up to 1.8.9
- Fixed in:
- 1.9.0
- Disclosed:
- Feb 7, 2024
CVE-2024-0620 on NVD →
PPWP – WordPress Password Protect Page <= 1.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The WordPress Password Protect Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contri...
- CVSS:
- 6.4
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.6
- Disclosed:
- Jan 10, 2023
CVE-2022-4626 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database