CVE-2026-90952
Received
Received - Intake
WP Edit Password Protected WordPress Plugin REST API Exposure
Vulnerability report for CVE-2026-90952, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-02
Last updated on: 2026-10-02
Assigner: WPScan
Description
Description
The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| artus_kg | wp_edit_password_protected | to 2.0.7 (exc) |
| artus_kg | wp_edit_password_protected | 2.0.0 |
| artus_kg | wp_edit_password_protected | 2.0.6 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |