Known vulnerabilities in Prevent Direct Access – Protect WordPress Files
A simple way to prevent search engines and the public from indexing and accessing your files without complex user authentication.
3Reported vulnerabilities
5.4Highest CVSS score
2.8.9.0Latest version
10,000+Active installs
What to do now
Update Prevent Direct Access – Protect WordPress Files to 2.8.8.9 or later.
3 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-3861 | Medium | 0.3% | 2.8.6 to 2.8.8.2 (inclusive) | 2.8.8.3 |
April 25, 2025 |
| CVE-2026-3835 | Medium | 0.3% | 0 to 2.8.8.8 (inclusive) | 2.8.8.9 |
August 13, 2026 |
| CVE-2025-3923 | Medium | 0.4% | 0 to 2.8.8 (inclusive) | 2.8.8.1 |
April 25, 2025 |