CVE-2026-90952 PUBLISHED

WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST API

Assigner: WPScan
Reserved: 14.09.2026 Published: 02.10.2026 Updated: 02.10.2026

The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor Unknown
Product WP Edit Password Protected
Versions Default: unaffected
  • affected from 2.0.0 to 2.0.7 (excl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE