Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High0
Medium3
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2025-07-03

CVE-2024-11297 - Page Restriction Plugin

The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.6 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.

PLUGIN Page Restriction

CVE-2024-11297

MEDIUM CVSS 5.3 2024-12-20
Threat Entry Updated 2025-03-11

CVE-2024-0681 - Page Restriction Plugin

The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.3.4. This is due to the plugin not properly restricting access to pages via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected pages. The vendor has decided that they will not implement REST API protection on posts and pages and the restrictions will only apply to the front-end of the site. The vendors solution…

PLUGIN Page Restriction

CVE-2024-0681

MEDIUM CVSS 5.3 2024-03-13
Threat Entry Updated 2024-11-21

CVE-2022-1027 - Page Restriction Plugin

The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the settings page to inject Javascript code to its settings leading to stored Cross-Site Scripting that will only affect administrator users.

PLUGIN Page Restriction

CVE-2022-1027

MEDIUM CVSS 4.8 2022-04-25
Scroll to top