plugin

Protect Wp Admin Vulnerabilities

8 known security issues reported for the Protect Wp Admin WordPress plugin. Most recent disclosed Dec 16, 2025.

1 high 3 medium

Running Protect Wp Admin on your site? Check whether your installed version is affected.

Scan your site free

Protect WP Admin [protect-wp-admin] <= 4.1 (unfixed)

unknown

[en] Missing Authorization vulnerability in WP-EXPERTS.IN Protect WP Admin protect-wp-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Protect WP Admin: from n/a through <= 4.1.

Affected:
up to 4.1
Fix:
No patched version reported
Disclosed:
Dec 16, 2025

CVE-2025-64249 on NVD →

Protect WP Admin <= 4.1 - Missing Authorization

medium

The Protect WP Admin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 4.1
Fixed in:
4.2
Disclosed:
Dec 15, 2025

CVE-2025-64249 on NVD →

Protect WP Admin [protect-wp-admin] < 4.0

unknown

[en] The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.

Affected:
up to 4.0
Fixed in:
4.0
Disclosed:
Jul 4, 2023

CVE-2023-3139 on NVD →

Protect WP Admin <= 3.8 - Unauthenticated Information Disclosure to Protection Bypass

medium

The Protect WP Admin plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 3.8. This is due to a data leak when performing a redirect after processing a crafted request. This makes it possible for unauthenticated attackers to disclose the URL of the admin panel and bypass intend...

CVSS:
5.3
Affected:
up to 3.8
Fixed in:
4.0
Disclosed:
Jun 12, 2023

CVE-2023-3139 on NVD →

Protect WP Admin <= 3.7 - Cross-Site Scripting

medium

The Protect WP Admin plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 3.7
Fixed in:
3.8
Disclosed:
Aug 5, 2022

Protect WP Admin [protect-wp-admin] < 3.8

unknown

The Protect WP Admin plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 3.8
Fixed in:
3.8
Disclosed:
Aug 5, 2022

Protect WP Admin [protect-wp-admin] < 3.7

unknown

[en] The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request

Affected:
up to 3.7
Fixed in:
3.7
Disclosed:
Jan 24, 2022

CVE-2021-24906 on NVD →

Protect WP Admin <= 3.6 - Unauthenticated Plugin Deactivation

high

The Protect WP Admin WordPress plugin before 3.7 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request

CVSS:
7.5
Affected:
up to 3.6
Fixed in:
3.7
Disclosed:
Dec 23, 2021

CVE-2021-24906 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database