WordPress Plugin Vulnerabilities
Restrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass via REST API Route Normalization
Description
The plugin does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Shivamani Vastrala
Submitter
Shivamani Vastrala
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-31 (about 2 days ago)
Added
2026-08-31 (about 2 days ago)
Last Updated
2026-08-31 (about 2 days ago)