The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.3.4. This is due to the plugin not properly restricting access to pages via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected pages. The vendor has decided that they will not implement REST API protection on posts and pages and the restrictions will only apply to the front-end of the site. The vendors solution was to add notices throughout the dashboard and recommends installing the WordPress REST API Authentication plugin for REST API coverage.
History

Tue, 11 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Miniorange
Miniorange page Restriction
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:miniorange:page_restriction:*:*:*:*:*:wordpress:*:*
Vendors & Products Miniorange
Miniorange page Restriction

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-08T20:02:18.711Z

Reserved: 2024-01-18T13:55:00.721Z

Link: CVE-2024-0681

cve-icon Vulnrichment

Updated: 2024-08-01T18:11:35.735Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-13T16:15:12.767

Modified: 2025-03-11T13:33:45.277

Link: CVE-2024-0681

cve-icon Redhat

No data.