The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-12 06:19
Updated : 2026-08-26 16:30
NVD link : CVE-2026-18035
Mitre link : CVE-2026-18035
CVE.ORG link : CVE-2026-18035
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
