CVE-2025-8945
Received Received - Intake

Password Protection Bypass via REST API in WP Edit Password Protected

Vulnerability report for CVE-2025-8945, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: WPScan

Description

The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wp_edit password_protected to 1.3.5 (exc)
wp_edit_password_protected wp_edit_password_protected to 1.3.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress plugin 'Wp Edit Password Protected' versions before 1.3.5. It allows unauthorized users to bypass password protection on page content by using the REST API endpoint /wp-json/wp/v2/pages/[id] without authentication.

Detection Guidance

Check if your WordPress site uses the Wp Edit Password Protected plugin version below 1.3.5. Use the REST API endpoint /wp-json/wp/v2/pages/[id] to request protected page content without authentication. If content is returned, the site is vulnerable.

Impact Analysis

An attacker could access protected page content without credentials, potentially exposing sensitive information. This could lead to data leaks, unauthorized access to private pages, or compliance violations if the content contains regulated data.

Compliance Impact

This vulnerability could lead to unauthorized access to protected data, violating GDPR's data protection principles or HIPAA's confidentiality requirements. Organizations using this plugin may face compliance breaches and potential penalties.

Mitigation Strategies

Update the Wp Edit Password Protected plugin to version 1.3.5 or later immediately. If updating is not possible, consider disabling the plugin temporarily until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-8945. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart