Unrated severityNVD Advisory· Published Aug 14, 2025· Updated Aug 14, 2025
PPWP < 1.9.11 - Subscriber+ Access Bypass via REST API
CVE-2025-5998
Description
The PPWP – Password Protect Pages WordPress plugin before version 1.9.11 allows to put the site content behind a password authorization, however users with subscriber or greater roles can view content via the REST API.
Affected products
2- WordPress/PPWP – Password Protect Pages plugindescription
- Range: <1.9.11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/17bad181-6cea-445e-b91c-22415d90743e/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.