Loading market data...
← Back to CVE feed

CVE-2026-90952

MEDIUM CVSS 5.3 View on NVD ↗

Description

The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Published: Oct 02, 2026 07:16 UTC Modified: Oct 02, 2026 18:00 UTC