CVE-2025-8945 Overview
CVE-2025-8945 is an authorization flaw in the WP Edit Password Protected WordPress plugin in versions prior to 1.3.5. The plugin restricts access to protected page content through its front-end rendering logic, but the WordPress REST API endpoints do not enforce the same protection. Unauthenticated attackers can retrieve protected content by querying the REST API directly, bypassing the password gate entirely. The issue maps to CWE-863: Incorrect Authorization.
Critical Impact
Unauthenticated remote users can read the contents of password-protected pages by issuing standard REST API requests to affected WordPress sites.
Affected Products
- WP Edit Password Protected WordPress plugin versions before 1.3.5
- WordPress sites relying on this plugin to gate page content
- Any deployment exposing the WordPress REST API to unauthenticated clients
Discovery Timeline
- 2026-09-02 - CVE-2025-8945 published to the National Vulnerability Database
- 2026-09-02 - Last updated in NVD database
Technical Details for CVE-2025-8945
Vulnerability Analysis
The WP Edit Password Protected plugin adds a password requirement to pages that would otherwise be public. The enforcement runs inside the standard WordPress template rendering path, gating the page body until a valid password is submitted. The REST API served through /wp-json/wp/v2/pages follows a separate code path and returns page content based on WordPress core capability checks rather than the plugin's password logic. Because the plugin never registers a REST-side authorization filter, protected content is returned in the JSON response without any password prompt.
The confidentiality impact is limited to content the plugin was intended to hide. Integrity and availability are unaffected because the API path used for the bypass exposes read operations only.
Root Cause
The root cause is missing authorization on an alternate access path. The plugin implements access control at the presentation layer but does not hook into rest_prepare_page or a comparable filter to strip or block protected content in API responses. This is a textbook [CWE-863] scenario in which one interface enforces a policy that a parallel interface ignores.
Attack Vector
An unauthenticated attacker sends an HTTP GET request to the WordPress REST API endpoint for pages on a target site running a vulnerable version of the plugin. The response includes the rendered content of pages that should require a password. No authentication, user interaction, or elevated privileges are required. Consult the WPScan Vulnerability Report for endpoint-level details.
Detection Methods for CVE-2025-8945
Indicators of Compromise
- Unauthenticated GET requests to /wp-json/wp/v2/pages or /wp-json/wp/v2/pages/<id> from unfamiliar source IP addresses
- Web server access logs showing REST API calls for page IDs known to be password-protected
- Repeated enumeration of sequential page IDs via the REST API in a short timeframe
Detection Strategies
- Inventory installed WordPress plugins and flag any WP Edit Password Protected installation with a version below 1.3.5
- Correlate REST API access logs with the list of pages configured as password-protected in the plugin settings
- Alert on anonymous REST API requests returning HTTP 200 responses for content classified as restricted
Monitoring Recommendations
- Forward WordPress and web server logs into a centralized analytics platform for query and correlation
- Track baseline request volume to /wp-json/wp/v2/pages and alert on statistically significant spikes
- Monitor plugin version drift across managed WordPress fleets so out-of-date instances surface quickly
How to Mitigate CVE-2025-8945
Immediate Actions Required
- Upgrade the WP Edit Password Protected plugin to version 1.3.5 or later on every affected WordPress site
- Audit REST API access logs for prior unauthenticated reads of protected page IDs
- Rotate any sensitive information that was exposed through protected pages if evidence of access exists
Patch Information
The vendor addressed the issue in version 1.3.5 of the WP Edit Password Protected plugin. Administrators should apply the update through the WordPress plugin manager or by deploying the packaged release. Refer to the WPScan Vulnerability Report for the fixed version reference.
Workarounds
- Disable the WP Edit Password Protected plugin until the patched version can be installed
- Restrict access to the WordPress REST API using an authentication requirement plugin or reverse-proxy rule
- Block unauthenticated requests to /wp-json/wp/v2/pages/<id> for page IDs that must remain confidential
# Example nginx rule to require authentication on the pages REST endpoint
location ~ ^/wp-json/wp/v2/pages {
auth_basic "Restricted";
auth_basic_user_file /etc/nginx/.htpasswd;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
