Passwordprotectwp develops a WordPress plugin focused on access protection and authentication, with vulnerabilities concentrated in this single product around input handling and information exposure. The recurring weakness classes reflect typical authentication-layer risks in WordPress plugin ecosystems where access controls and data handling are central to function. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Passwordprotectwp over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-5998MEDIUM The PPWP – Password Protect Pages WordPress plugin before version 1.9.11 allows to put the site content behind a password authorization, however users with subscriber or greater ro | Aug 14, 2025 | 6.5 | 22 | NO | NO |
CVE-2022-4626MEDIUM The PPWP WordPress plugin before 1.8.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as | Feb 6, 2023 | 5.4 | 20 | NO | NO |
CVE-2024-0620MEDIUM The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. This makes it possible f | Feb 29, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Passwordprotectwp.
Media articles that mention a CVE ID that affects a product developed by Passwordprotectwp — matched by CVE ID, not by vendor name.