Sceawere
Vulnerability Detail
CVE-2026-90952UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Edit Password Protected REST API Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 16h ago
- Vendor
- Unknown
- Product
- WP Edit Password Protected
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-02T07:16:38.243Z",
"pubdate": "2026-10-02T07:16:38.243Z",
"executiveSummary": "The WP Edit Password Protected WordPress plugin, in versions prior to 2.0.7, suffers from an Improper Access Control vulnerability within its WordPress REST API implementation.\nThe vulnerability allows unauthenticated remote attackers to bypass site-wide access restrictions configured by the administrator.\nBy leveraging the exposed REST API endpoints, unauthorized users can access and read the contents of published posts and pages that were intended to be restricted to authenticated or authorized users only.\nThis flaw effectively negates the security mechanism provided by the plugin, leading to the exposure of sensitive or private content.\nThe risk is categorized as high, as it requires no authentication and can be exploited by any remote actor with network access to the target WordPress instance.\nExploitation does not require elevated privileges or complex interaction, facilitating the unauthorized retrieval of restricted data via simple HTTP GET requests to the REST API.",
"technicalDetails": "The vulnerability exists because the plugin fails to properly verify the site-wide access control policies when processing requests made through the WordPress REST API infrastructure.\nWhile the plugin is designed to restrict access to the frontend content of the site based on a password-protected mode or specific visibility configurations, it lacks an integrated hook or filter to enforce these same restrictions on the wp-json/wp/v2/posts and wp-json/wp/v2/pages endpoints.\nIn a standard WordPress environment, the REST API endpoints often default to exposing content that is set to a 'publish' status. The WP Edit Password Protected plugin attempts to intercept these requests to prevent unauthorized access, but it fails to cover the REST API route entirely.\nAn unauthenticated attacker can exploit this by crafting HTTP requests targeting the REST API endpoints. By querying the endpoints directly, the attacker bypasses the plugin's frontend access control logic, which relies on cookies or session management that is absent in the API interaction flow.\nThe attack flow proceeds as follows: First, the attacker identifies a WordPress site utilizing the vulnerable version of the WP Edit Password Protected plugin. Second, the attacker targets the site's REST API endpoints (e.g., /wp-json/wp/v2/posts). Third, since the plugin fails to validate the current access-restricted state during the API request lifecycle, the WordPress REST API controller processes the request normally. Fourth, the server returns the post or page content in a JSON format to the unauthenticated attacker, completely circumventing the intended protection mechanism.\nThis failure effectively exposes any content stored within the database as a post or page, regardless of the password-protection or access-mode settings defined in the plugin configuration. The vulnerability resides in the core plugin logic responsible for gating content accessibility. The exposure is total for the REST API surface, meaning that any content accessible via these endpoints is at risk of unauthorized retrieval. This poses a significant confidentiality threat, as attackers can scrape or exfiltrate content intended only for authorized site visitors."
}