PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-8945 Wp Edit Password Protected CVE debrief

The Wp Edit Password Protected WordPress plugin before 1.3.5 has a vulnerability allowing protection bypass via the REST API. This issue has a CVSS score of 5.3 and is classified as MEDIUM severity. Affected product deployments should be identified in managed environments, and owners should be assigned for follow-up. The CVE record was published on 2026-09-02T15:17:36.993Z and has not been modified since then. Limited details are available; verify plugin version and REST API usage.

Vendor
Wp Edit Password Protected
Product
Wp Edit Password Protected
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-03
Advisory published
2026-09-02
Advisory updated
2026-09-03

Who should care

WordPress site administrators using the Wp Edit Password Protected plugin, security teams monitoring for REST API anomalies, and operators managing affected deployments should prioritize patching and review compensating controls for exposed systems while remediation is scheduled and verified. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Affected operator, platform, vulnerability-management, and security-team impact should be assessed to ensure proper mitigation and exposure review. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Asset inventory and source tracking are crucial for effective vulnerability management in this context. Rollback change windows should be considered if immediate patching is not feasible. Monitoring and detection capabilities should be reviewed to ensure they can identify potential exploitation attempts. Compensating controls, such as restricting REST API access, should be implemented to mitigate the vulnerability until patching can be completed. Vendor patch guidance should be followed closely to ensure the vulnerability is properly addressed. Exposure review should be conducted to identify potential vulnerabilities and prioritize mitigation efforts. Compensating controls, such as implementing additional security measures, should be considered to reduce the risk of exploitation. Monitoring and detection capabilities should be reviewed to ensure they can identify potential exploitation attempts. Asset inventory and source tracking are crucial for effective vulnerability management in this context. Rollback change windows should be considered if immediate patching is not feasible. Monitoring and detection capabilities should be reviewed to ensure they can identify potential exploitation attempts. Compensating controls, such as restricting REST API access, should be implemented to mitigate the vulnerability until patching.

Technical summary

The Wp Edit Password Protected WordPress plugin before 1.3.5 has a vulnerability allowing protection bypass via the REST API. This issue has a CVSS score of 5.3 and is classified as MEDIUM severity. The vulnerability allows protecting page content, but this protection can be bypassed by using the REST API. Review and restrict REST API access to sensitive content. Monitor for suspicious REST API activity.

Defensive priority

Medium-severity vulnerability in a WordPress plugin; prioritize patching.

Recommended defensive actions

  • Patch the Wp Edit Password Protected WordPress plugin to version 1.3.5 or later
  • Review and restrict REST API access to sensitive content
  • Monitor for suspicious REST API activity

Evidence notes

The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API. Limited details are available; verify plugin version and REST API usage.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-8945 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-8945

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-8945 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-8945

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.