The Restrict User Access – Ultimate Membership & Content Protection plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via API. This makes it possible for unauthenticated attackers to obtain the contents of posts and pages via API.
References
Configurations
History
11 Mar 2025, 13:32
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3037773%40restrict-user-access%2Ftrunk&old=3010745%40restrict-user-access%2Ftrunk&sfp_email=&sfph_mail= - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/f67684cd-3e0f-48bb-967a-16ea2b027843?source=cve - Third Party Advisory | |
CPE | cpe:2.3:a:dev.institute:restrict_user_access:*:*:*:*:*:wordpress:*:* | |
CWE | NVD-CWE-noinfo | |
First Time |
Dev.institute
Dev.institute restrict User Access |
Information
Published : 2024-03-13 16:15
Updated : 2025-03-11 13:32
NVD link : CVE-2024-0687
Mitre link : CVE-2024-0687
CVE.ORG link : CVE-2024-0687
JSON object : View
Products Affected
dev.institute
- restrict_user_access
CWE