What is CVE-2026-3639?
A Stored Cross-Site Scripting (XSS) vulnerability has been found in the PPWP – Password Protect Pages plugin for WordPress, affecting all versions up to and including 1.9.21. The flaw exists in the 'ppwp' shortcode attributes due to insufficient input sanitization and output escaping of user-supplied data. Users should immediately update the plugin to the patched version and review for any potentially injected malicious scripts.
Azərbaycanca: WordPress üçün PPWP – Password Protect Pages plaginində, 1.9.21 daxil olmaqla bütün versiyalara təsir edən Stored Cross-Site Scripting (XSS) zəifliyi aşkarlanıb. Bu boşluq 'ppwp' shortcode atributlarında kifayət qədər input sanitization və output escaping olmaması səbəbindən yaranır. İstifadəçilər plagini dərhal ən son versiyaya yeniləməli və şübhəli kontenti nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the PPWP plugin for WordPress are affected by CVE-2026-3639?
This Stored XSS vulnerability affects all versions of the PPWP – Password Protect Pages plugin up to and including 1.9.21.
What is the root cause of CVE-2026-3639?
The flaw exists because of insufficient input sanitization and output escaping of user-supplied data in the 'ppwp' shortcode attributes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.