CVE-2026-12426
MEDIUMMembers <= 3.2.22 - Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel
Title source: cnaDescription
The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.22 via the members_filter_protected_posts_for_rest. This makes it possible for unauthenticated attackers to extract determine the existence and exact count of access-restricted posts, and use per-page pagination as a boolean oracle to infer keywords and content contained within those hidden restricted posts.
References (6)
Core 6
Core References
Scores
CVSS v3
5.3
EPSS
0.0027
EPSS Percentile
19.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (1)
supercleanse/Members – Membership & User Role Editor Plugin
< 3.2.22
Published
Jul 11, 2026
Tracked Since
Jul 11, 2026