CVE-2026-90952
Received Received - Intake

WP Edit Password Protected WordPress Plugin REST API Exposure

Vulnerability report for CVE-2026-90952, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: WPScan

Description

The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
artus_kg wp_edit_password_protected to 2.0.7 (exc)
artus_kg wp_edit_password_protected 2.0.0
artus_kg wp_edit_password_protected 2.0.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WP Edit Password Protected WordPress plugin before version 2.0.7 has a vulnerability where site-wide access restrictions are not enforced on the WordPress REST API. This allows unauthenticated users to read content from published posts and pages that were intended to be hidden by the plugin's access settings.

Detection Guidance

Check the installed version of the WP Edit Password Protected plugin. If it is between 2.0.0 and 2.0.6, the system is vulnerable. Use WordPress admin panel or run: wp plugin list --name='wp-edit-password-protected' in the WordPress directory.

Impact Analysis

This vulnerability allows unauthorized users to access restricted content on your WordPress site without authentication. If you use the plugin to hide sensitive posts or pages, attackers could view them through the REST API, potentially exposing private information.

Compliance Impact

This vulnerability could lead to non-compliance with data protection regulations like GDPR or HIPAA if it exposes protected personal or health information. Unauthorized access to restricted content may violate privacy requirements and result in legal or regulatory penalties.

Mitigation Strategies

Update the WP Edit Password Protected plugin to version 2.0.7 or later immediately. Disable the plugin temporarily if an update is not immediately available. Review REST API responses to ensure protected content is not exposed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90952. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart