A vulnerability was found in buildwps PPWP Password Protect Pages Plugin up to 1.9.21 on WordPress. It has been declared as problematic . Affected by this issue is some unknown functionality of the component shortcode Handler . The manipulation results in cross site scripting. This vulnerability is identified as CVE-2026-3639 . The attack can be executed remotely. There is not any exploit available.