Password Protected <= 2.8.3 - Unauthenticated Information Exposure
medium
The Password Protected plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.3. This is due to a missing authentication check in the REST API access filter, which allowed the 'Allow REST API' option to bypass password protection for all visitors rather than only logg...
- CVSS:
- 5.3
- Affected:
- up to 2.8.3
- Fixed in:
- 2.8.4
- Disclosed:
- Aug 3, 2026
CVE-2026-14943 on NVD →
Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content [password-protected] < 2.7.12
unknown
[en] The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is due to the plugin trusting client-controlled HTTP headers (such as X-Forwarded-For, HTTP_CLIENT_IP, and similar headers) to determine user IP addresses in...
- Affected:
- up to 2.7.12
- Fixed in:
- 2.7.12
- Disclosed:
- Oct 25, 2025
CVE-2025-11244 on NVD →
Password Protected <= 2.7.11 - Unauthenticated Authorization Bypass via IP Address Spoofing
low
The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is due to the plugin trusting client-controlled HTTP headers (such as X-Forwarded-For, HTTP_CLIENT_IP, and similar headers) to determine user IP addresses in the `...
- CVSS:
- 3.7
- Affected:
- up to 2.7.11
- Fixed in:
- 2.7.12
- Disclosed:
- Oct 24, 2025
CVE-2025-11244 on NVD →
Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products <= 2.7.7 - Unauthenticated Sensitive Information Exposure
medium
The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.7 via the 'password_protected_cookie' function. This makes...
- CVSS:
- 5.3
- Affected:
- up to 2.7.7
- Fixed in:
- 2.7.8
- Disclosed:
- Apr 16, 2025
CVE-2025-3453 on NVD →
Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease <= 2.6.6 - Missing Authorization to Sensitive Information Exposure
medium
The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the API. This makes it possible for authenticated attackers, with subscriber access or higher, to extract pos...
- CVSS:
- 4.3
- Affected:
- up to 2.6.6
- Fixed in:
- 2.6.7
- Disclosed:
- May 14, 2024
CVE-2024-0437 on NVD →
Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content [password-protected] < 2.6.7
unknown
[en] The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the API. This makes it possible for authenticated attackers, with subscriber access or higher, to extrac...
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.7
- Disclosed:
- May 14, 2024
CVE-2024-0437 on NVD →
Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content [password-protected] < 2.6.7
unknown
[en] The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Captcha Site Key in all versions up to, and including, 2.6.6 due to insufficient input sanitization and output escaping. This makes it possi...
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.7
- Disclosed:
- Feb 20, 2024
CVE-2024-0656 on NVD →
Password Protected <= 2.6.6 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Captcha Site Key in all versions up to, and including, 2.6.6 due to insufficient input sanitization and output escaping. This makes it possible f...
- CVSS:
- 4.4
- Affected:
- up to 2.6.6
- Fixed in:
- 2.6.7
- Disclosed:
- Feb 19, 2024
CVE-2024-0656 on NVD →
Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content [password-protected] < 2.6.3
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPExperts Password Protected plugin <= 2.6.2 versions.
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.3
- Disclosed:
- Jun 23, 2023
CVE-2023-32580 on NVD →
Password Protected <= 2.6.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Password Protected plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitra...
- CVSS:
- 4.4
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.3
- Disclosed:
- Jun 13, 2023
CVE-2023-32580 on NVD →
Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content [password-protected] < 1.5
unknown
This plugin is prone to login process redirect_to parameter arbitrary site redirect vulnerability.
Upgrade the plugin.
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Nov 27, 2015
Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content [password-protected] < 2.6.3.2
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.6.3.2
- Fixed in:
- 2.6.3.2
CVE-2023-33999 on NVD →
Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content [password-protected] < 1.5
unknown
The Password Protected WordPress plugin was affected by a Login Process redirect_to Parameter Arbitrary Site Redirect security vulnerability.
- Affected:
- up to 1.5
- Fixed in:
- 1.5
Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content [password-protected] < 2.7.8
unknown
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.8
CVE-2025-3453 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database