plugin

Password Protect Page Vulnerabilities

11 known security issues reported for the Password Protect Page WordPress plugin. Most recent disclosed Aug 24, 2026.

1 high 10 medium

Running Password Protect Page on your site? Check whether your installed version is affected.

Scan your site free

Password Protect WordPress Lite <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ppwp' shortcode in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it...

CVSS:
6.4
Affected:
up to 1.9.21
Fixed in:
1.9.22
Disclosed:
Aug 24, 2026

CVE-2025-9878 on NVD →

PPWP – Password Protect Pages <= 1.9.18 - Authenticated (Contributor+) PHP Object Injection via post_protection_roles

high

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deserialization of untrusted input from the 'post_protection_roles' vulnerable parameter. This makes it possible for authenticated attackers, with Contributor-level access and ab...

CVSS:
8.8
Affected:
up to 1.9.18
Fixed in:
1.9.19
Disclosed:
Aug 22, 2026

CVE-2026-0551 on NVD →

PPWP: Password Protect Pages, Posts & Full or Partial Content <= 1.9.15 - Improper Authorization To Authenticated (Contributor+) Master Password Exposure

medium

The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the can_access function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Contributor-level acces...

CVSS:
4.3
Affected:
up to 1.9.15
Fixed in:
1.9.16
Disclosed:
Aug 18, 2026

CVE-2025-11729 on NVD →

Password Protect WordPress Lite <= 1.9.20 - Insecure Direct Object Reference to Authenticated (Contributor+) Password Protected Post Password Update

medium

The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.20 via the ppw_free_set_password AJAX action due to missing validation on a user controlled key. This makes it possible for authentica...

CVSS:
4.3
Affected:
up to 1.9.20
Fixed in:
1.9.21
Disclosed:
Aug 15, 2026

CVE-2025-10005 on NVD →

PPWP – Password Protect Pages <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

medium

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a...

CVSS:
6.4
Affected:
up to 1.9.21
Fixed in:
1.9.22
Disclosed:
Aug 12, 2026

CVE-2026-3639 on NVD →

PPWP – Password Protect Pages <= 1.9.19 - Authenticated (Contributor+) Insecure Direct Object Reference

medium

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.19 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorize...

CVSS:
4.3
Affected:
up to 1.9.19
Fixed in:
1.9.20
Disclosed:
Jun 26, 2026

CVE-2026-57634 on NVD →

PPWP – Password Protect Pages <= 1.9.15 - Missing Authorization

medium

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.9.15
Fixed in:
1.9.16
Disclosed:
Mar 23, 2026

CVE-2026-32562 on NVD →

PPWP – Password Protect Pages <= 1.9.10 - Authenticated (Subscriber+) Content Exposure via REST API

medium

The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.10 due to insufficient protection on REST API endpoints when password protection is enabled. This makes it possible for unauthenticated...

CVSS:
4.3
Affected:
up to 1.9.10
Fixed in:
1.9.11
Disclosed:
Aug 25, 2025

CVE-2025-5998 on NVD →

PPWP – Password Protect Pages <= 1.9.5 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

medium

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level ro...

CVSS:
5.3
Affected:
up to 1.9.5
Fixed in:
1.9.6
Disclosed:
Dec 16, 2024

CVE-2024-11280 on NVD →

PPWP – Password Protect Pages <= 1.8.9 - Protection Mechanism Bypass

medium

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. This makes it possible for unauthenticated attackers to obtain post titles, IDs, slugs as well as other information including for password-protected posts.

CVSS:
5.3
Affected:
up to 1.8.9
Fixed in:
1.9.0
Disclosed:
Feb 7, 2024

CVE-2024-0620 on NVD →

PPWP – WordPress Password Protect Page <= 1.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The WordPress Password Protect Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.8.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contri...

CVSS:
6.4
Affected:
up to 1.8.5
Fixed in:
1.8.6
Disclosed:
Jan 10, 2023

CVE-2022-4626 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database