The Page Restrict plugin for WordPress is vulnerable to...
Moderate severity
Unreviewed
Published
Feb 28, 2024
to the GitHub Advisory Database
•
Updated Apr 8, 2026
Description
Published by the National Vulnerability Database
Feb 28, 2024
Published to the GitHub Advisory Database
Feb 28, 2024
Last updated
Apr 8, 2026
The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5.5. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected posts.
References