plugin

Page And Post Restriction Vulnerabilities

4 known security issues reported for the Page And Post Restriction WordPress plugin. Most recent disclosed Aug 4, 2026.

1 high 3 medium

Running Page And Post Restriction on your site? Check whether your installed version is affected.

Scan your site free

Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API

high

The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the WordPress core REST endpoints /wp-json/wp/v2/pages, /wp-json/wp/v2/pages/<id>, /wp-json/wp/v2/posts, and /wp-json/wp/v2/posts/<id>. This is due to the plugin's REST guards — p...

CVSS:
7.5
Affected:
up to 1.4.1
Fixed in:
1.4.2
Disclosed:
Aug 4, 2026

CVE-2026-12000 on NVD →

Page Restriction WordPress (WP) – Protect WP Pages/Post <= 1.3.6 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

medium

The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.6 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been res...

CVSS:
5.3
Affected:
up to 1.3.6
Fixed in:
1.3.7
Disclosed:
Dec 19, 2024

CVE-2024-11297 on NVD →

Page Restriction WordPress (WP) – Protect WP Pages/Post <= 1.3.4 - Protection Mechanism Bypass

medium

The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.3.4. This is due to the plugin not properly restricting access to pages via the REST API when a page has been made private. This makes it possible for unauthen...

CVSS:
5.3
Affected:
up to 1.3.4
Fixed in:
1.3.5
Disclosed:
Feb 27, 2024

CVE-2024-0681 on NVD →

Page Restriction WordPress <= 1.2.6 - Admin+ Stored Cross-Site Scripting

medium

The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the settings page to inject Javascript code to its settings leading to stored Cross-Site Scripting that will only affect administrator users.

CVSS:
5.5
Affected:
up to 1.2.6
Fixed in:
1.2.7
Disclosed:
Apr 9, 2022

CVE-2022-1027 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database