WordPress Plugin Vulnerabilities
Members < 3.2.23 - Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel
Description
The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.22 via the members_filter_protected_posts_for_rest. This makes it possible for unauthenticated attackers to extract determine the existence and exact count of access-restricted posts, and use per-page pagination as a boolean oracle to infer keywords and content contained within those hidden restricted posts.
Affects Plugins
References
Classification
Type
SENSITIVE DATA DISCLOSURE
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Huazu Jiang (anjhz0318)
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-07-10 (about 1 month ago)
Added
2026-07-10 (about 1 month ago)
Last Updated
2026-07-11 (about 1 month ago)