Password for WP
Password for WP has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Password for WP has a vendor fix available, so running the current release closes it.
All of these findings were reported by SOPROBRO. Password for WP is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-11419Password for WP <= 1.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Password for WP
Author
get3code
Password for WP locks your whole website behind one password. Visitors see a clean, full-screen login screen until they enter the correct password, while your WordPress admin area (wp-admin) stays fully accessible. It is perfect for sites in development, staging environments, private launches, client previews, or a simple maintenance mode. Setup takes less than a minute and the plugin is completely free. Key features Protect the entire front-end of the site with one password. Modern, responsive login screen with a clean, flat design. Choose a background image from the WordPress Media Library and display it stretched as a full cover, with a live thumbnail preview in the settings. Set a custom background color used as a fallback behind the image. Add your own headings (H2 and H3) to greet or inform visitors. Cache support: keeps the protection working when a page cache plugin is active (LiteSpeed Cache, WP Super Cache, W3 Total Cache and more). Skip the password for logged-in users with a single switch. CSRF-protected settings and hardened output escaping. Available in English, Polish, German and French, and fully translation ready. How it works When protection is enabled, every front-end request is checked for a valid access cookie. Visitors without the cookie are shown the login screen. After entering the correct password, a secure cookie is set for 30 days so they are not asked again. The WordPress login and admin panel are never blocked by the plugin. Upgrading For manual upgrades via FTP, deactivate and reactivate the plugin to ensure it works correctly. Translations Password for WP ships with English, Polish, German and French translations. Additional languages can be added using the included .po and .mo files in the /languages folder.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C