Protected Posts Logout Button
Protected Posts Logout Button has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 3 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.5 out of 10. 2023 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (33%). Other recurring categories include Cross-Site Scripting, Missing Authorization.
Every one of the 3 issues recorded for Protected Posts Logout Button has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by yuyudhn. Protected Posts Logout Button is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.1.12.
CVE-2023-25454Protected Posts Logout Button <= 1.4.5 - Missing Authorization on pplb_options_save
Read the full analysisVulnerability Records
Protected Posts Logout Button
Author
Nate Reist
This plugin simply adds a logout button to the content of any password protected post. Sometimes clients want a password protected page to share information with privileged individuals and the default 10 days for the cookie to expire is too long for their liking. So I wrote a little plugin to do this with AJAX and set the cookie to expire immediately, well actually 10 days in the past. Works logged in or out as a WordPress user. Uses the same functionality WordPress uses to set post cookies. Has a simple settings page to make everything easier. Allows you to alert user they have logged out.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C