The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users. | |
| Title | Restrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass via REST API Route Normalization | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-09-02T14:16:51.343Z
Updated: 2026-09-02T14:57:37.398Z
Reserved: 2026-08-23T06:59:08.195Z
Link: CVE-2026-78153
Updated: 2026-09-02T14:43:55.232Z
Status : Deferred
Published: 2026-09-02T15:17:39.810
Modified: 2026-09-03T17:50:37.690
Link: CVE-2026-78153
No data.