The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.3.4. This is due to the plugin not properly restricting access to pages via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected pages. The vendor has decided that they will not implement REST API protection on posts and pages and the restrictions will only apply to the front-end of the site. The vendors solution was to add notices throughout the dashboard and recommends installing the WordPress REST API Authentication plugin for REST API coverage.
History

Wed, 08 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Title Page Restriction WordPress (WP) – Protect WP Pages/Post <= 1.3.4 - Protection Mechanism Bypass
Weaknesses CWE-693

Tue, 11 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Miniorange
Miniorange page Restriction
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:miniorange:page_restriction:*:*:*:*:*:wordpress:*:*
Vendors & Products Miniorange
Miniorange page Restriction

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-03-13T15:27:08.355Z

Updated: 2026-04-08T17:12:54.551Z

Reserved: 2024-01-18T13:55:00.721Z

Link: CVE-2024-0681

cve-icon Vulnrichment

Updated: 2024-08-01T18:11:35.735Z

cve-icon NVD

Status : Modified

Published: 2024-03-13T16:15:12.767

Modified: 2026-04-08T19:19:15.350

Link: CVE-2024-0681

cve-icon Redhat

No data.