CVE-2024-0909

MEDIUM

Anonymous Restricted Content <1.6.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Anonymous Restricted Content plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.6.2. This is due to insufficient restrictions through the REST API on the posts/pages that protections are being place on. This makes it possible for unauthenticated attackers to access protected content.

Scores

CVSS v3 5.3
EPSS 0.0061
EPSS Percentile 44.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
cayenne/Anonymous Restricted Content < 1.6.2
cayenne/anonymous_restricted_content < 1.6.2
Published Feb 03, 2024
Tracked Since Feb 18, 2026