PT-2024-15945 · WordPress · Simple Page Access Restriction

Francesco Carlucci

·

Published

2024-02-08

·

Updated

2024-02-15

·

CVE-2024-0965

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Simple Page Access Restriction plugin for WordPress versions up to, and including, 1.0.21
Description The issue allows unauthenticated attackers to bypass page restrictions and view page content via the REST API. This is possible due to Sensitive Information Exposure in the plugin.
Recommendations For versions up to, and including, 1.0.21, update to a version later than 1.0.21 to resolve the issue. As a temporary workaround, consider restricting access to the REST API endpoints to minimize the risk of exploitation.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-0965

Affected Products

Simple Page Access Restriction