ZIP Code Based Content Protection
ZIP Code Based Content Protection has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 6.2, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is SQL Injection, behind 2 of the records (100%).
Every one of the 2 issues recorded for ZIP Code Based Content Protection has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. ZIP Code Based Content Protection is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-14353ZIP Code Based Content Protection <= 1.0.2 - Unauthenticated SQL Injection via 'zipcode' Parameter
Read the full analysisVulnerability Records

ZIP Code Based Content Protection
Author
PressTigers
ZIP Code Based Content Protection comes in handy when you want the visitor to input ZIP Code before showing them any kind of content. And the content will be shown if that certain ZIP Code is allowed for that particular content. Situations like when you want to show details of a community meeting, promotions and offers on a certain service, event details etc or any kind of content which the admin wants the user to go through by entering the allowed ZIP Code, ZBCP can assist. Below are some salient features: ZBCP Features Simple to use 100% responsive Can be enabled on all available post types Custom message settings Can track most requested ZIP Codes Custom ZIP Codes Track visitor email addresses As we continue to strive for perfection further features will be added in future updates. DO YOU WANT TO CONTRIBUTE? If you have ideas that can help us improve our plugin and user experience, please contact us at support@presstigers.com
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C