The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. This makes it possible for unauthenticated attackers to obtain post titles, IDs, slugs as well as other information including for password-protected posts.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2024-16413 | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. This makes it possible for unauthenticated attackers to obtain post titles, IDs, slugs as well as other information including for password-protected posts. | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Mon, 27 Jan 2025 17:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Passwordprotectwp
         Passwordprotectwp password Protect Wordpress  | 
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:passwordprotectwp:password_protect_wordpress:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products | 
        
        Passwordprotectwp
         Passwordprotectwp password Protect Wordpress  | 
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-07T17:49:02.616Z
Reserved: 2024-01-16T18:25:24.705Z
Link: CVE-2024-0620
Updated: 2024-08-01T18:11:35.681Z
Status : Analyzed
Published: 2024-02-29T01:43:23.493
Modified: 2025-01-27T17:28:48.890
Link: CVE-2024-0620
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD