CVE-2026-78153 PUBLISHED

Restrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass via REST API Route Normalization

Assigner: WPScan
Reserved: 23.08.2026 Published: 02.09.2026 Updated: 02.09.2026

The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor Unknown
Product Restrict User Access
Versions Default: unaffected
  • affected from 2.6 to 2.8.1 (excl.)

Credits

  • Shivamani Vastrala finder
  • WPScan coordinator

References

Problem Types

  • CWE-863 Incorrect Authorization CWE