What the vulnerability does
01Description
The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.8 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.
Explanation of Vulnerability in Simple Terms
02Summary
The Restrict plugin for WordPress contains an information exposure vulnerability that allows unauthenticated attackers to read sensitive data over the network without user interaction. The plugin fails to properly restrict access to certain information, exposing details that should be protected. All versions up to 2.2.8 are affected. Site administrators should update to a version newer than 2.2.8 as soon as possible.
What an attacker can do
03Attacker Capabilities
Read sensitive information that should be restricted, such as membership details or access control settings.
Potential impact on your site
04Site Impact
Confidential membership, access control, or user data may be exposed to unauthenticated visitors.
Conditions required to exploit
05Prerequisites
No authentication or user interaction required; attacker needs only network access to the site.
Key dates
06Disclosure timeline
December 11, 2024
CVE published
April 8, 2026
Record updated