The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue
We have discovered 307 live websites that are affected by CVE-2025-9034.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 307 live websites (42% of Wp Edit Password Protected install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 10 versions ( 71% of all versions) |
| 103 websites | |
| 33 websites | |
| 23 websites | |
| 15 websites | |
| 14 websites | |
| 13 websites | |
| 12 websites | |
| 5 websites | |
| 5 websites | |
| 5 websites |
| .com | 127 websites |
| .org | 31 websites |
| .de | 17 websites |
| .co.uk | 12 websites |
| .it | 11 websites |
| .nl | 9 websites |
| .ca | 5 websites |
| .pl | 5 websites |
| .net | 5 websites |
| .info | 5 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.com | ***,*** | ||
| *****.********.net | ***,*** | ||
| *******.com | ***,*** | ||
| *****.info | ***,*** | ||
| **********.com | ***,*** | ||
| ********.com | *,***,*** | ||
| ******.*******.edu | *,***,*** | ||
| ************.de | *,***,*** | ||
| ****************.com | *,***,*** | ||
| ********.eu | *,***,*** |
FAQ