CVE-2024-0687

MEDIUM

Restrict User Access - Info Disclosure

Title source: llm
STIX 2.1

Description

The Restrict User Access – Ultimate Membership & Content Protection plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via API. This makes it possible for unauthenticated attackers to obtain the contents of posts and pages via API.

Scores

CVSS v3 5.3
EPSS 0.0055
EPSS Percentile 41.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
dev.institute/restrict_user_access < 2.6
intoxstudio/Restrict User Access – Ultimate Membership & Content Protection < 2.5
Published Mar 13, 2024
Tracked Since Feb 18, 2026