CVE-2024-11351 MEDIUM

CVE-2024-11351: Restrict – membership, site, content and user access restrictions for WordPress <= 2.2.8 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure

Vendor Tickera
Product Restrict – membership, site, content and user access restrictions for WordPress
Weakness CWE-200 · Info exposure
Published December 11, 2024
Last update April 8, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.8 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.

Explanation of Vulnerability in Simple Terms

02Summary

The Restrict plugin for WordPress contains an information exposure vulnerability that allows unauthenticated attackers to read sensitive data over the network without user interaction. The plugin fails to properly restrict access to certain information, exposing details that should be protected. All versions up to 2.2.8 are affected. Site administrators should update to a version newer than 2.2.8 as soon as possible.

What an attacker can do

03Attacker Capabilities

Read sensitive information that should be restricted, such as membership details or access control settings.

Potential impact on your site

04Site Impact

Confidential membership, access control, or user data may be exposed to unauthenticated visitors.

Conditions required to exploit

05Prerequisites

No authentication or user interaction required; attacker needs only network access to the site.

Key dates

06Disclosure timeline

December 11, 2024 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE