SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15939

LOW · CVSS 2.7 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

The Simple Restrict WordPress plugin prior to version 1.2.9 has a vulnerability in its REST API that bypasses the intended content-restriction permissions, allowing users with contributor-level access or higher to view restricted posts and pages. This flaw can lead to unauthorized access to sensitive content, posing a risk to site confidentiality. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exposure.

CVE
CVE-2026-15939
Severity
LOW
CVSS
2.7
EPSS
0.18%
WordPress

Original NVD Description

The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission system, allowing users with contributor-level access or above to read the content of restricted posts and pages they were never granted access to.