CVE-2026-78153

The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 15:17

Updated : 2026-09-03 17:50


NVD link : CVE-2026-78153

Mitre link : CVE-2026-78153

CVE.ORG link : CVE-2026-78153


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization