CVE-2026-15939
Received Received - Intake

Unauthorized Content Access in Simple Restrict WordPress Plugin

Vulnerability report for CVE-2026-15939, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-02

Last updated on: 2026-08-02

Assigner: WPScan

Description

The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission system, allowing users with contributor-level access or above to read the content of restricted posts and pages they were never granted access to.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-02
Last Modified
2026-08-02
Generated
2026-08-02
AI Q&A
2026-08-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
simple_restrict plugin to 1.2.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Simple Restrict WordPress plugin before version 1.2.9 has a flaw where it does not properly enforce its content-restriction permissions on the REST API. Unlike the front end, which uses the plugin's specific permission system, the REST API relies on a generic capability check. This allows users with contributor-level access or higher to read restricted posts and pages they should not have access to.

Detection Guidance

To detect this vulnerability, check if your Simple Restrict WordPress plugin is outdated. Run commands like 'wp plugin list' to verify the installed version. If it's below 1.2.9, the vulnerability may exist.

Impact Analysis

If you use the Simple Restrict WordPress plugin before version 1.2.9, unauthorized users with contributor-level access or above could read content that was meant to be restricted. This could lead to data leaks, unauthorized access to sensitive information, or violation of intended access controls.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if restricted content includes personal or sensitive data. Unauthorized access to such data may result in legal penalties, fines, or reputational damage due to violations of data protection requirements.

Mitigation Strategies

Update the Simple Restrict WordPress plugin to version 1.2.9 or later to ensure proper permission checks are enforced on the REST API.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15939. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart