Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API
high
The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the WordPress core REST endpoints /wp-json/wp/v2/pages, /wp-json/wp/v2/pages/<id>, /wp-json/wp/v2/posts, and /wp-json/wp/v2/posts/<id>. This is due to the plugin's REST guards — p...
- CVSS:
- 7.5
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.2
- Disclosed:
- Aug 4, 2026
CVE-2026-12000 on NVD →
Page Restriction WordPress (WP) – Protect WP Pages/Post <= 1.3.6 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
medium
The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.6 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been res...
- CVSS:
- 5.3
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.7
- Disclosed:
- Dec 19, 2024
CVE-2024-11297 on NVD →
Page Restriction WordPress (WP) – Protect WP Pages/Post <= 1.3.4 - Protection Mechanism Bypass
medium
The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.3.4. This is due to the plugin not properly restricting access to pages via the REST API when a page has been made private. This makes it possible for unauthen...
- CVSS:
- 5.3
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.5
- Disclosed:
- Feb 27, 2024
CVE-2024-0681 on NVD →
Page Restriction WordPress <= 1.2.6 - Admin+ Stored Cross-Site Scripting
medium
The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the settings page to inject Javascript code to its settings leading to stored Cross-Site Scripting that will only affect administrator users.
- CVSS:
- 5.5
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.7
- Disclosed:
- Apr 9, 2022
CVE-2022-1027 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database