CVE-2025-9034

Wp Edit Password Protected < 1.3.5 - Open Redirect

The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue


We have discovered 307 live websites that are affected by CVE-2025-9034.

Run a Free Instant Scan




Affected Software

Product  Wp Edit Password Protected
Category Wordpress Plugins
Vulnerable Domains307 live websites (42% of Wp Edit Password Protected install base)
Vulnerable Versions
  • from 0 through 1.3.5
Vulnerable Versions Count10 versions ( 71% of all versions)


Common Weakness Enumeration

CWE-601 URL Redirection to Untrusted Site ('Open Redirect')



Details

  • Published - Sep 11, 2025
  • Updated - Sep 11, 2025

Credits

  • Bob Matyas (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2025-9034
United States103 websites



Germany33 websites
GB23 websites
Italy15 websites
Canada14 websites
France13 websites
Netherlands12 websites
Poland5 websites
Denmark5 websites
Sweden5 websites

Website Distribution by TLD

Number of websites using CVE-2025-9034
.com127 websites
.org31 websites
.de17 websites
.co.uk12 websites
.it11 websites
.nl9 websites
.ca5 websites
.pl5 websites
.net5 websites
.info5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-9034

Top websites that are affected by CVE-2025-9034. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com GB***,***
*****.********.net Germany***,***
*******.com France***,***
*****.info Italy***,***
**********.com United States***,***
********.com United States*,***,***
******.*******.edu United States*,***,***
************.de Germany*,***,***
****************.com United States*,***,***
********.eu Czech Republic*,***,***
See full domain list

FAQ

CVE-2025-9034 is URL Redirection to Untrusted Site ('Open Redirect') in Wp Edit Password Protected
A total of 307 websites have been identified as vulnerable to CVE-2025-9034, based on global website indexing conducted by WebTechSurvey.
The Wp Edit Password Protected is affected by the CVE-2025-9034 vulnerability.
Wp Edit Password Protected versions up to 1.3.5 are vulnerable to CVE-2025-9034.
CVE-2025-9034 is resolved in version 1.3.5 of Wp Edit Password Protected.