๐Ÿ” CVE Alert

CVE-2026-15939

UNKNOWN 0.0

Simple Restrict < 1.2.9 - Contributor+ Restricted Content Disclosure via REST API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission system, allowing users with contributor-level access or above to read the content of restricted posts and pages they were never granted access to.

Vendor unknown
Product simple restrict
Published Aug 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown simple restrict

Be the first to know when new unknown vulnerabilities affecting unknown simple restrict are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Simple Restrict
0 < 1.2.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/307a3033-ca65-4c3a-9a08-dd4a6f7dacea/

Credits

Shikhali Jamalzade WPScan