WordPress Plugin Vulnerabilities

Simple Restrict < 1.2.9 - Contributor+ Restricted Content Disclosure via REST API

Description

The plugin does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the plugin's own permission system, allowing users with contributor-level access or above to read the content of restricted posts and pages they were never granted access to.

Proof of Concept

Affects Plugins

Fixed in 1.2.9

References

Classification

Type
INCORRECT AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Shikhali Jamalzade
Submitter
Shikhali Jamalzade
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-07-20 (about 6 days ago)
Added
2026-07-20 (about 6 days ago)
Last Updated
2026-07-20 (about 6 days ago)

Other