← back to popular plugins
wordfence / plugin · password-protect-page
PPWP – Password Protect Pages
password-protect-page
total installs
30,000
total vulns
2
critical
0
high
0
medium
2
low
0
latest vuln
—
patched
2
unpatched
0
avg time to patch
—
vulnerabilities
(2)
PPWP – Password Protect Pages <= 1.9.15 - Missing Authorization
medium
✓ patched
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
PPWP – Password Protect Pages <= 1.9.10 - Authenticated (Subscriber+) Content Exposure via REST API
medium
✓ patched
cve id
CVE-2025-5998 ↗
cvss score
4.3
cwe
CWE-280: Improper Handling of Insufficient Permissions or Privileges
published
Aug 25, 2025
The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.10 due to insufficient protection on REST API endpoints when password protection is enabled. This makes it possible for unauthenticated attackers to extract post and page content that should be hidden.