CVE-2026-14943
Password Protected < 2.8.4 - Unauthenticated Sensitive Information Exposure via REST API
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content and account identifiers via the REST API. This re-introduces a previously-fixed issue (CVE-2024-0437), which was patched in 2.6.7 and regressed in 2.6.8.
| Vendor | unknown |
| Product | password protected — lock entire site, pages, posts, categories, and partial content |
| Published | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown password protected — lock entire site, pages, posts, categories, and partial content
Be the first to know when new unknown vulnerabilities affecting unknown password protected — lock entire site, pages, posts, categories, and partial content are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content
2.6.8 < 2.8.4
References
Credits
Revanth Hari Narayana Matte WPScan