CVE-2025-8945: Wp Edit Password Protected < 1.3.5 - Protection Bypass via REST API
Published Sep 2, 2026
·Updated
The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API.
Affected Software
1 affected component
Wp Edit Password Protected<1.3.5
Event History
Sep 2, 2026
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any remote, unauthenticated attacker can exploit it because the vulnerability has network access, low attack complexity, and requires no privileges or user interaction.
2
What content is exposed?
Page content protected by the plugin may be accessible through the WordPress REST API despite the configured password protection.
3
How can I determine whether my site is affected?
Sites using Wp Edit Password Protected versions earlier than 1.3.5 are affected. Check the installed plugin version and test whether password-protected page content can be retrieved through the REST API without supplying the page password.