CVE-2025-11244: Password Protected <= 2.7.11 - Unauthenticated Authorization Bypass via IP Address Spoofing

Published Oct 25, 2025
·
Updated

The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is due to the plugin trusting client-controlled HTTP headers (such as X-Forwarded-For, HTTPCLIENTIP, and similar headers) to determine user IP addresses in the ppgetipaddress() function when the "Use transients" feature is enabled. This makes it possible for attackers to bypass authorization by spoofing these headers with the IP address of a legitimately authenticated user, granted the "Use transients" option is enabled (non-default configuration) and the site is not behind a CDN or reverse proxy that overwrites these headers.

Affected Software

1 affected component
WordPress Password Protected<=2.7.11

Event History

Oct 25, 2025
CVE Published
via MITRE·05:31 AM
Data Sourced
via MITRE·05:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-11244?

CVE-2025-11244 has a high severity due to the potential for unauthorized access through IP address spoofing.

2

How do I fix CVE-2025-11244?

To fix CVE-2025-11244, update the Password Protected plugin to version 2.7.12 or later, which addresses this vulnerability.

3

What versions are affected by CVE-2025-11244?

CVE-2025-11244 affects all versions of the Password Protected plugin for WordPress up to and including version 2.7.11.

4

What type of attack is CVE-2025-11244 associated with?

CVE-2025-11244 is associated with unauthorized access attacks leveraging IP address spoofing.

5

Who is at risk with CVE-2025-11244?

Users of the Password Protected plugin for WordPress who have not updated beyond version 2.7.11 are at risk from CVE-2025-11244.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203