Htaccess by BestWebSoft – WordPress Website Access Control Plugin
Htaccess by BestWebSoft – WordPress Website Access Control Plugin has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2017 and 2020; all 2 are fixed as of September 2026. Their average CVSS score is 7.5, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
Every one of the 2 issues recorded for Htaccess by BestWebSoft – WordPress Website Access Control Plugin has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Htaccess by BestWebSoft – WordPress Website Access Control Plugin is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2020-8658Htaccess <= 1.8.1 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Htaccess by BestWebSoft – WordPress Website Access Control Plugin
Author
bestwebsoft
Htaccess plugin is a simple and useful tool which helps to control the access to your WordPress website. Allow or deny access based on a hostname, IP address, IP range, and others. Disable hotlinking and access to xmlrpc.php. Easily secure your WordPress website! View Demo Free Features Set the order fields: Allow, Deny Deny, Allow Set the argument info to the directive form: Allow Deny Customize .htaccess file Create a backup with the ability to restore .htaccess file Block by domain and by User Agent Compatible with latest WordPress version Incredibly simple settings for fast setup without modifying code Detailed step-by-step documentation and videos Multilingual and RTL ready Limit access to wp-admin by IP (one IP) Pro Features All features from Free version included plus: Set the access to the xmlrpc.php: Access deny Redirect to the main page Enable/disable hotlinking Block domain with .htaccess file Separate file for blocked and allowed ips Allow hotlinking based on hostnames Configure all subsites on the network Limit access to wp-admin by IP (many IP) Get answer to your support question within one business day (Support Policy) Upgrade to Pro Now If you have a feature suggestion or idea you’d like to see in the plugin, we’d love to hear about it! Suggest a Feature Documentation & Videos [Doc] User Guide [Doc] Installation [Doc] Purchase [Video] Installation Instruction Help & Support Visit our Help Center if you have any questions, our friendly Support Team is happy to help — https://support.bestwebsoft.com/ Translation Polish (pl_PL) (thanks to Damian Dąbrowski) Russian (ru_RU) Ukrainian (uk) Some of these translations are not complete. We are constantly adding new features which should be translated. If you would like to create your own language pack or update the existing one, you can send the text of PO and MO files to BestWebSoft and we’ll add it to the plugin. You can download the latest version of the program for work with PO and MO files Poedit. Recommended Plugins Updater – Automatically check and update WordPress website core with all installed plugins and themes to the latest versions. Limit Attempts – Protect WordPress website against brute force attacks. Limit rate of login attempts.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C