🔐 CVE Alert

CVE-2026-14943

HIGH 7.5

Password Protected < 2.8.4 - Unauthenticated Sensitive Information Exposure via REST API

CVSS Score
7.5
EPSS Score
0.1%
EPSS Percentile
4th

The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content and account identifiers via the REST API. This re-introduces a previously-fixed issue (CVE-2024-0437), which was patched in 2.6.7 and regressed in 2.6.8.

Vendor unknown
Product password protected — lock entire site, pages, posts, categories, and partial content
Published Aug 7, 2026
Last Updated Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for unknown password protected — lock entire site, pages, posts, categories, and partial content

Be the first to know when new high vulnerabilities affecting unknown password protected — lock entire site, pages, posts, categories, and partial content are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content
2.6.8 < 2.8.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/874ada86-f13b-44f9-85e6-f2ec16e82f85/

Credits

Revanth Hari Narayana Matte WPScan