CyberRota Analysis
AI-GeneratedThe Simple Restrict WordPress plugin prior to version 1.2.9 has a vulnerability in its REST API that bypasses the intended content-restriction permissions, allowing users with contributor-level access or higher to view restricted posts and pages. This flaw can lead to unauthorized access to sensitive content, posing a risk to site confidentiality. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exposure.
Original NVD Description
The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission system, allowing users with contributor-level access or above to read the content of restricted posts and pages they were never granted access to.