The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5.5. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected posts.

Project Subscriptions

Vendors Products
Theandystratton Subscribe
Page Restrict Subscribe
Pagerestrict Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-16473 The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5.5. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected posts.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 08 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Theandystratton page Restrict
CPEs cpe:2.3:a:theandystratton:page_restrict:*:*:*:*:*:*:*:*
Vendors & Products Theandystratton page Restrict
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 17:45:00 +0000

Type Values Removed Values Added
Title Page Restrict <= 2.5.5 - Protection Mechanism Bypass
Weaknesses CWE-693

Fri, 07 Feb 2025 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Theandystratton
Theandystratton pagerestrict
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:theandystratton:pagerestrict:*:*:*:*:*:wordpress:*:*
Vendors & Products Theandystratton
Theandystratton pagerestrict

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:57:27.383Z

Reserved: 2024-01-18T13:59:35.007Z

Link: CVE-2024-0682

cve-icon Vulnrichment

Updated: 2024-08-01T18:11:35.727Z

cve-icon NVD

Status : Modified

Published: 2024-02-28T09:15:41.573

Modified: 2026-04-08T18:18:56.327

Link: CVE-2024-0682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses