wpchill Vulnerabilities and Affected Products
Vulnerabilities associated with Simple Restrict.
Products
Clear product- Download Monitor12 vulnerabilities
- Kali Forms — Contact Form & Drag-and-Drop Builder10 vulnerabilities
- Strong Testimonials7 vulnerabilities
- Modula Image Gallery – Photo Grid & Video Gallery6 vulnerabilities
- Image Photo Gallery Final Tiles Grid5 vulnerabilities
- Passster – Password Protect Pages and Content5 vulnerabilities
- download_monitor3 vulnerabilities
- Brilliance2 vulnerabilities
- Filr – Secure document library2 vulnerabilities
- Gallery PhotoBlocks (WordPress plugin)2 vulnerabilities
- Image Gallery – Photo Grid & Video Gallery2 vulnerabilities
- Qyrr – simply and modern QR-Code creation2 vulnerabilities
- Simple Restrict2 vulnerabilities
- simple_restrict2 vulnerabilities
- Affluent1 vulnerability
- Allegiant1 vulnerability
- CPO Companion1 vulnerability
- CPO Content Types1 vulnerability
- CPO Shortcodes1 vulnerability
- CPO Shortcodes (WordPress plugin)1 vulnerability
- Download Monitor (WordPress plugin)1 vulnerability
- Download Monitor plugin for WordPress1 vulnerability
- Gallery PhotoBlocks1 vulnerability
- imageseo1 vulnerability
- Lightbox – EverlightBox Gallery1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-11106MEDIUM | Simple Restrict <= 1.2.7 - Unauthenticated Content Restriction Bypass to Sensitive Information ExposureThe Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.7 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator. CWE-200Dec 10, 2024 | CVSS5.3v3.1 | EPSS0.374% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-1083MEDIUM | Simple Restrict <= 1.2.6 - Missing Authorization to Sensitive Information ExposureThe Simple Restrict plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.6 via the REST API. This makes it possible for authenticated attackers to bypass the plugin's restrictions to extract post titles and content CWE-200Mar 13, 2024 | CVSS5.3v3.1 | EPSS0.542% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |