Simple Page Access Restriction <= 1.0.32 - Cross-Site Request Forgery
medium
The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.32. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can tr...
- CVSS:
- 4.3
- Affected:
- up to 1.0.32
- Fixed in:
- 1.0.33
- Disclosed:
- Aug 27, 2025
CVE-2025-58202 on NVD →
Simple Page Access Restriction <= 1.0.31 - Cross-Site Request Forgery via Multiple Parameters
medium
The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due to missing nonce validation and capability checks in the settings save handler in the settings.php script. This makes it possible for unauthenticated attackers to...
- CVSS:
- 6.5
- Affected:
- up to 1.0.31
- Fixed in:
- 1.0.32
- Disclosed:
- May 29, 2025
CVE-2025-5142 on NVD →
Simple Page Access Restriction <= 1.0.29 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
medium
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level...
- CVSS:
- 5.3
- Affected:
- up to 1.0.29
- Fixed in:
- 1.0.30
- Disclosed:
- Dec 17, 2024
CVE-2024-11295 on NVD →
Simple Page Access Restriction <= 1.0.21 - Improper Access Control to Sensitive Information Exposure via REST API
medium
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's page restriction and view page content.
- CVSS:
- 5.3
- Affected:
- up to 1.0.21
- Fixed in:
- 1.0.23
- Disclosed:
- Feb 7, 2024
CVE-2024-0965 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database