Multiple Post Passwords

Multiple Post Passwords has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Multiple Post Passwords has a vendor fix available, so running the current release closes it.

All of these findings were reported by DoYeon Park (p6rkdoye0n). Multiple Post Passwords is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
4.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Multiple Post Passwords vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.4CVE-2023-49157

Multiple Post Passwords <= 1.1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Multiple Post Passwords banner
Latestv1.1.4

Multiple Post Passwords

Andreas Münch

Author

Andreas Münch

5.0(11)
100/100
Last Updated
2026-01-17 (8mo ago)
Active Installs
2,000+
Downloads
25,864
Requires WP
4.7.0+
Requires PHP
5.6+
Tested up to
WP 6.8.8
Created
2018-10-25 (8y ago)

This is a simple Plugin that lets you set multiple passwords for your password protected posts and pages. On posts/pages with password protection it will show an extra Metabox with a field to input additional passwords, one in each line. Note that if you just changed a post/page to password protection you have to save once so that the extra field appears. Expire passwords You can also make passwords expire after x hours when being used. You can find the settings under Settings -> Multiple Post Passwords. Note that the actual deletion of the passwords is triggered by a cronjob which is run every 30 minutes. So even if you set your expiry time to very short, it may still take 30 minutes until the password really expires. Also note that the expiration only works for the additional passwords, not for the standard WordPress page/post password. Using lots of passwords on one page If you are using lots of passwords on one page and the password check takes a long time, you should activate the alternative password check in the settings to speed up the password check.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C