Stored Cross-Site Scripting Vulnerability in PPWP - Password Protect WordPress Plugin
CVE-2025-9878
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 August 2026
What is CVE-2025-9878?
A vulnerability exists in the PPWP - Password Protect WordPress plugin that allows authenticated users with contributor-level access and above to exploit insufficient input sanitization and output escaping. This flaw facilitates the injection of arbitrary web scripts through the 'ppwp' shortcode, leading to malicious code execution on any page accessed by users. All plugin versions up to and including 1.9.21 are affected, presenting a significant risk to WordPress sites utilizing this popular password protection tool.
Affected Version(s)
PPWP β Password Protect Pages 0 <= 1.9.21