Insecure Direct Object Reference in PPWP Password Protect WordPress Plugin
CVE-2025-10005
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
What is CVE-2025-10005?
The PPWP β Password Protect WordPress plugin is susceptible to an Insecure Direct Object Reference, affecting all versions up to 1.9.20. This vulnerability arises from inadequate validation on a user-controlled key within the ppw_free_set_password AJAX action. As a result, authenticated attackers with Contributor-level access or higher can change passwords for any password-protected posts, granting them unauthorized access to restricted content.
Affected Version(s)
PPWP β Password Protect Pages 0 <= 1.9.20