plugin

Simple Page Access Restriction Vulnerabilities

4 known security issues reported for the Simple Page Access Restriction WordPress plugin. Most recent disclosed Aug 27, 2025.

4 medium

Running Simple Page Access Restriction on your site? Check whether your installed version is affected.

Scan your site free

Simple Page Access Restriction <= 1.0.32 - Cross-Site Request Forgery

medium

The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.32. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can tr...

CVSS:
4.3
Affected:
up to 1.0.32
Fixed in:
1.0.33
Disclosed:
Aug 27, 2025

CVE-2025-58202 on NVD →

Simple Page Access Restriction <= 1.0.31 - Cross-Site Request Forgery via Multiple Parameters

medium

The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due to missing nonce validation and capability checks in the settings save handler in the settings.php script. This makes it possible for unauthenticated attackers to...

CVSS:
6.5
Affected:
up to 1.0.31
Fixed in:
1.0.32
Disclosed:
May 29, 2025

CVE-2025-5142 on NVD →

Simple Page Access Restriction <= 1.0.29 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

medium

The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level...

CVSS:
5.3
Affected:
up to 1.0.29
Fixed in:
1.0.30
Disclosed:
Dec 17, 2024

CVE-2024-11295 on NVD →

Simple Page Access Restriction <= 1.0.21 - Improper Access Control to Sensitive Information Exposure via REST API

medium

The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's page restriction and view page content.

CVSS:
5.3
Affected:
up to 1.0.21
Fixed in:
1.0.23
Disclosed:
Feb 7, 2024

CVE-2024-0965 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database