Htaccess by BestWebSoft – WordPress Website Access Control Plugin

Htaccess by BestWebSoft – WordPress Website Access Control Plugin has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2017 and 2020; all 2 are fixed as of September 2026. Their average CVSS score is 7.5, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.

Every one of the 2 issues recorded for Htaccess by BestWebSoft – WordPress Website Access Control Plugin has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Htaccess by BestWebSoft – WordPress Website Access Control Plugin is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSHigh
7.5/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Htaccess by BestWebSoft – WordPress Website Access Control Plugin vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2020-8658

Htaccess <= 1.8.1 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

2 records
Htaccess by BestWebSoft – WordPress Website Access Control Plugin banner
Latestv1.8.9

Htaccess by BestWebSoft – WordPress Website Access Control Plugin

bestwebsoft

Author

bestwebsoft

4.0(2)
80/100
Last Updated
2026-04-24 (5mo ago)
Active Installs
300+
Downloads
42,925
Requires WP
6.2+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2014-02-11 (13y ago)

Htaccess plugin is a simple and useful tool which helps to control the access to your WordPress website. Allow or deny access based on a hostname, IP address, IP range, and others. Disable hotlinking and access to xmlrpc.php. Easily secure your WordPress website! View Demo Free Features Set the order fields: Allow, Deny Deny, Allow Set the argument info to the directive form: Allow Deny Customize .htaccess file Create a backup with the ability to restore .htaccess file Block by domain and by User Agent Compatible with latest WordPress version Incredibly simple settings for fast setup without modifying code Detailed step-by-step documentation and videos Multilingual and RTL ready Limit access to wp-admin by IP (one IP) Pro Features All features from Free version included plus: Set the access to the xmlrpc.php: Access deny Redirect to the main page Enable/disable hotlinking Block domain with .htaccess file Separate file for blocked and allowed ips Allow hotlinking based on hostnames Configure all subsites on the network Limit access to wp-admin by IP (many IP) Get answer to your support question within one business day (Support Policy) Upgrade to Pro Now If you have a feature suggestion or idea you’d like to see in the plugin, we’d love to hear about it! Suggest a Feature Documentation & Videos [Doc] User Guide [Doc] Installation [Doc] Purchase [Video] Installation Instruction Help & Support Visit our Help Center if you have any questions, our friendly Support Team is happy to help — https://support.bestwebsoft.com/ Translation Polish (pl_PL) (thanks to Damian Dąbrowski) Russian (ru_RU) Ukrainian (uk) Some of these translations are not complete. We are constantly adding new features which should be translated. If you would like to create your own language pack or update the existing one, you can send the text of PO and MO files to BestWebSoft and we’ll add it to the plugin. You can download the latest version of the program for work with PO and MO files Poedit. Recommended Plugins Updater – Automatically check and update WordPress website core with all installed plugins and themes to the latest versions. Limit Attempts – Protect WordPress website against brute force attacks. Limit rate of login attempts.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C