Protect WP Admin
Protect WP Admin has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2025; all 4 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Scripting, behind 1 of the records (25%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Incorrect Authorization.
Every one of the 4 issues recorded for Protect WP Admin has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. Protect WP Admin is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2021-24906Protect WP Admin <= 3.6 - Unauthenticated Plugin Deactivation
Read the full analysisVulnerability Records

Protect WP Admin
Author
WP-EXPERTS.IN
Protect WP Admin adds an extra security layer to your WP site by allowing you to rename and secure the wp-admin and wp-login.php URLs. Change default admin URL (e.g., /wp-admin to /myadmin) Restrict access to dashboard by roles or specific user IDs Customize login page colors and logo Block access to default login URLs Stop bots and hackers from brute-forcing your login page. This plugin is ideal for any site looking to increase login security without modifying core files. Video Demo: https://youtu.be/Mxr2MLDNACE Pro Add-on Available: Click here to download add-on Features Define Custom WP Admin Login URL (e.g., http://yourdomain.com/myadmin) Add custom logo and styling to login page Restrict wp-admin access to only admin or defined user IDs Redirect all unauthorized users and bots Pro Features Rename wp-admin completely Set login attempt limits Track login history Change usernames More style controls Get the Pro Version: Protect WP Admin Pro License This plugin is licensed under the GPLv2 or later. https://www.gnu.org/licenses/gpl-2.0.html
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C