Protected Posts Logout Button

Protected Posts Logout Button has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 3 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.5 out of 10. 2023 was the busiest year with 3 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (33%). Other recurring categories include Cross-Site Scripting, Missing Authorization.

Every one of the 3 issues recorded for Protected Posts Logout Button has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by yuyudhn. Protected Posts Logout Button is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.1.12.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Protected Posts Logout Button vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.5CVE-2023-25454

Protected Posts Logout Button <= 1.4.5 - Missing Authorization on pplb_options_save

Read the full analysis

Vulnerability Records

3 records
Plugin Profile
Latestv1.4.6

Protected Posts Logout Button

Nate Reist

Author

Nate Reist

4.9(13)
98/100
Last Updated
2023-02-16 (4y ago)
Active Installs
1,000+
Downloads
34,158
Requires WP
2.8+
Requires PHP
0+
Tested up to
WP 6.1.12
Created
2012-05-16 (15y ago)

This plugin simply adds a logout button to the content of any password protected post. Sometimes clients want a password protected page to share information with privileged individuals and the default 10 days for the cookie to expire is too long for their liking. So I wrote a little plugin to do this with AJAX and set the cookie to expire immediately, well actually 10 days in the past. Works logged in or out as a WordPress user. Uses the same functionality WordPress uses to set post cookies. Has a simple settings page to make everything easier. Allows you to alert user they have logged out.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C