Protect WP Admin [protect-wp-admin] <= 4.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in WP-EXPERTS.IN Protect WP Admin protect-wp-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Protect WP Admin: from n/a through <= 4.1.
- Affected:
- up to 4.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 16, 2025
CVE-2025-64249 on NVD →
Protect WP Admin <= 4.1 - Missing Authorization
medium
The Protect WP Admin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.1
- Fixed in:
- 4.2
- Disclosed:
- Dec 15, 2025
CVE-2025-64249 on NVD →
Protect WP Admin [protect-wp-admin] < 4.0
unknown
[en] The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Jul 4, 2023
CVE-2023-3139 on NVD →
Protect WP Admin <= 3.8 - Unauthenticated Information Disclosure to Protection Bypass
medium
The Protect WP Admin plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 3.8. This is due to a data leak when performing a redirect after processing a crafted request. This makes it possible for unauthenticated attackers to disclose the URL of the admin panel and bypass intend...
- CVSS:
- 5.3
- Affected:
- up to 3.8
- Fixed in:
- 4.0
- Disclosed:
- Jun 12, 2023
CVE-2023-3139 on NVD →
Protect WP Admin <= 3.7 - Cross-Site Scripting
medium
The Protect WP Admin plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 3.7
- Fixed in:
- 3.8
- Disclosed:
- Aug 5, 2022
Protect WP Admin [protect-wp-admin] < 3.8
unknown
The Protect WP Admin plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.7 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 3.8
- Fixed in:
- 3.8
- Disclosed:
- Aug 5, 2022
Protect WP Admin [protect-wp-admin] < 3.7
unknown
[en] The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request
- Affected:
- up to 3.7
- Fixed in:
- 3.7
- Disclosed:
- Jan 24, 2022
CVE-2021-24906 on NVD →
Protect WP Admin <= 3.6 - Unauthenticated Plugin Deactivation
high
The Protect WP Admin WordPress plugin before 3.7 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request
- CVSS:
- 7.5
- Affected:
- up to 3.6
- Fixed in:
- 3.7
- Disclosed:
- Dec 23, 2021
CVE-2021-24906 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database