Impact
The Password Protect Pages plugin contains an insufficiently sanitized ppwp shortcode that can store and render user‑supplied attributes as raw HTML. Attackers with Contributor or higher roles can inject arbitrary JavaScript into the shortcode’s attributes, which is then executed in any browser that views the affected page. This allows client‑side code execution, cookie theft, session hijacking, defacement or other malicious actions that affect confidentiality, integrity and availability of the site’s content for all visitors.
Affected Systems
The vulnerability applies to the PPWP – Password Protect Pages plugin by buildwps, in all releases up to and including 1.9.21. Sites running any of these versions and allowing contributors to edit pages are potentially impacted.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate‑severity flaw, while the absence of an EPSS value and its lack of inclusion in the CISA KEV catalog imply that exploit activity is currently undocumented. The most likely attack path involves an authenticated contributor adding a malicious ppwp shortcode to a post or page. Once the shortcode is stored, every user who views the page receives the injected script, making the vulnerability a strong opportunistic threat for sites with exposed contributor permissions.
OpenCVE Enrichment