Extension WordPress

Vulnérabilités Password Protected , Lock Entire Site, Pages, Posts, Categories, and Partial Content

Cette page rassemble les failles publiées pour Password Protected , Lock Entire Site, Pages, Posts, Categories, and Partial Content, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
0Critiques
5Avec correctif
5,3CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Password Protected , Lock Entire Site, Pages, Posts, Categories, and Partial Content

5 fiches

CVE-2025-11244 Faible · 3,7
Password Protected , Lock Entire Site, Pages, Posts, Categories, and Partial Content

Password Protected <= 2.7.11 – Unauthenticated Authorization Bypass via IP Address Spoofing

The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is due to the plugin trusting client-controlled HTTP headers (such as X-Forwarded-For, HTTP_CLIENT_IP, and…

Versions affectées

*-2.7.11

Correctif

2.7.12

Publication

24/10/2025

CVE-2025-3453 Moyenne · 5,3
Password Protected , Lock Entire Site, Pages, Posts, Categories, and Partial Content

Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products <= 2.7.7 – Unauthenticated Sensitive Information Exposure

The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.7…

Versions affectées

*-2.7.7

Correctif

2.7.8

Publication

16/04/2025

CVE-2024-0437 Moyenne · 4,3
Password Protected , Lock Entire Site, Pages, Posts, Categories, and Partial Content

Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease <= 2.6.6 – Missing Authorization to Sensitive Information Exposure

The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the API. This makes it possible…

Versions affectées

*-2.6.6

Correctif

2.6.7

Publication

14/05/2024

CVE-2024-0656 Moyenne · 4,4
Password Protected , Lock Entire Site, Pages, Posts, Categories, and Partial Content

Password Protected <= 2.6.6 – Authenticated (Admin+) Stored Cross-Site Scripting

The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Captcha Site Key in all versions up to, and including, 2.6.6 due…

Versions affectées

*-2.6.6

Correctif

2.6.7

Publication

19/02/2024

CVE-2023-32580 Moyenne · 4,4
Password Protected , Lock Entire Site, Pages, Posts, Categories, and Partial Content

Password Protected <= 2.6.2 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Password Protected plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-2.6.2

Correctif

2.6.3

Publication

13/06/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités