The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5.5. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected posts.
History

Fri, 07 Feb 2025 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Theandystratton
Theandystratton pagerestrict
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:theandystratton:pagerestrict:*:*:*:*:*:wordpress:*:*
Vendors & Products Theandystratton
Theandystratton pagerestrict

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-02-28T08:33:08.123Z

Updated: 2024-08-01T18:11:35.727Z

Reserved: 2024-01-18T13:59:35.007Z

Link: CVE-2024-0682

cve-icon Vulnrichment

Updated: 2024-08-01T18:11:35.727Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-28T09:15:41.573

Modified: 2025-02-07T01:26:17.227

Link: CVE-2024-0682

cve-icon Redhat

No data.