CVE-2025-9034: Unknown Wp Edit Password Protected

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

Affected products

  • Unknown Wp Edit Password Protected: before 1.3.5 (fixed in 1.3.5)

Published 2025-09-11. Last modified 2026-06-17.