← back to popular plugins
wordfence / plugin · password-protect-page

PPWP – Password Protect Pages

password-protect-page
total installs
30,000
total vulns
2
critical
0
high
0
medium
2
low
0
latest vuln
patched
2
unpatched
0
avg time to patch
vulnerabilities (2)
PPWP – Password Protect Pages <= 1.9.15 - Missing Authorization
medium ✓ patched
cvss score 4.3
cwe CWE-862: Missing Authorization
published Mar 23, 2026
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
PPWP – Password Protect Pages <= 1.9.10 - Authenticated (Subscriber+) Content Exposure via REST API
medium ✓ patched
cvss score 4.3
cwe CWE-280: Improper Handling of Insufficient Permissions or Privileges
published Aug 25, 2025
The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.10 due to insufficient protection on REST API endpoints when password protection is enabled. This makes it possible for unauthenticated attackers to extract post and page content that should be hidden.