
CVE-2026-3639 The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up to, … https://www.cve.org/CVERecord?id=CVE-2026-3639
Post summary
CVE-2026-3639 identifies a stored XSS vulnerability in the PPWP WordPress plugin via its ppwp shortcode attributes, affecting all versions up to the current release, with details referenced in the public CVE record.
