Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

WordPress Plugin: password-protect-page: CVE-2025-5998: Improper Handling of Insufficient Permissions or Privileges

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
Aug 25, 2025
Added
Aug 26, 2025
Modified
May 4, 2026

Description

The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.10 due to insufficient protection on REST API endpoints when password protection is enabled. This makes it possible for unauthenticated attackers to extract post and page content that should be hidden.

Solution

password-protect-page-plugin-cve-2025-5998
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.