Password for WP

Password for WP has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Password for WP has a vendor fix available, so running the current release closes it.

All of these findings were reported by SOPROBRO. Password for WP is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Password for WP vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2024-11419

Password for WP <= 1.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Password for WP banner
Latestv1.8.1

Password for WP

get3code

Author

get3code

0.0(0)
0/100
Last Updated
2026-06-19 (3mo ago)
Active Installs
200+
Downloads
4,656
Requires WP
6.0+
Requires PHP
7.2+
Tested up to
WP 7.0.4
Created
2020-02-21 (7y ago)

Password for WP locks your whole website behind one password. Visitors see a clean, full-screen login screen until they enter the correct password, while your WordPress admin area (wp-admin) stays fully accessible. It is perfect for sites in development, staging environments, private launches, client previews, or a simple maintenance mode. Setup takes less than a minute and the plugin is completely free. Key features Protect the entire front-end of the site with one password. Modern, responsive login screen with a clean, flat design. Choose a background image from the WordPress Media Library and display it stretched as a full cover, with a live thumbnail preview in the settings. Set a custom background color used as a fallback behind the image. Add your own headings (H2 and H3) to greet or inform visitors. Cache support: keeps the protection working when a page cache plugin is active (LiteSpeed Cache, WP Super Cache, W3 Total Cache and more). Skip the password for logged-in users with a single switch. CSRF-protected settings and hardened output escaping. Available in English, Polish, German and French, and fully translation ready. How it works When protection is enabled, every front-end request is checked for a valid access cookie. Visitors without the cookie are shown the login screen. After entering the correct password, a secure cookie is set for 30 days so they are not asked again. The WordPress login and admin panel are never blocked by the plugin. Upgrading For manual upgrades via FTP, deactivate and reactivate the plugin to ensure it works correctly. Translations Password for WP ships with English, Polish, German and French translations. Additional languages can be added using the included .po and .mo files in the /languages folder.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C