Impact
The PPWP – Password Protect Pages plugin is vulnerable to a stored Cross‑Site Scripting flaw through its ppwp shortcode attributes. Insufficient input sanitization and output escaping allow an authenticated user with contributor-level access or higher to inject arbitrary JavaScript into pages. When the affected page is viewed, the injected script executes in the victim’s browser, potentially leading to data theft, session hijacking, or defacement. This vulnerability falls under CWE‑79.
Affected Systems
A WordPress site running the PPWP – Password Protect Pages plugin from any buildwps build, specifically all versions up to and including 1.9.21. The problem exists in every release prior to 1.9.22, regardless of configuration, because the filtering deficiency is in the core shortcode handler.
Risk and Exploitability
The CVSS score of 6.4 indicates medium severity; the EPSS score is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalogue. Exploitation requires an authenticated user with contributor or higher permissions, so the threat is limited to accounts with write access to shortcode content. If such an account is compromised or a legitimate contributor misuses the shortcode, the vulnerability can be leveraged to deface or hijack sessions for any visitor to the impacted page. Given the lack of a publicly known zero‑day exploit, the risk remains medium unless the attacker gains contributor access.
OpenCVE Enrichment