medium · CVSS v3 5.3
CVE-2026-90952
The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the Wo…
Description
The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide.
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- —