CVE-2026-18035

The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-12 06:19

Updated : 2026-08-26 16:30


NVD link : CVE-2026-18035

Mitre link : CVE-2026-18035

CVE.ORG link : CVE-2026-18035


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization