What the vulnerability does
01Description
The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.13 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "Make Website Members Only" feature (when unset) and view restricted page and post content.
Explanation of Vulnerability in Simple Terms
02Summary
The WordPress Access Control plugin through version 4.0.13 contains an access control flaw that allows unauthenticated attackers to read sensitive information. The plugin fails to properly restrict access to certain data, exposing confidential details to anyone on the network. Site administrators should update the plugin immediately to a version newer than 4.0.13.
What an attacker can do
03Attacker Capabilities
Read sensitive information from the site without logging in.
Potential impact on your site
04Site Impact
Confidential data may be exposed to the public, including information not intended for unauthenticated users.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
February 28, 2024
CVE published
April 8, 2026
Record updated