The Anonymous Restricted Content plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.6.2. This is due to insufficient restrictions through the REST API on the posts/pages that protections are being place on. This makes it possible for unauthenticated attackers to access protected content.
References
Configurations
History
No history.
Information
Published : 2024-02-03 06:15
Updated : 2024-02-08 20:07
NVD link : CVE-2024-0909
Mitre link : CVE-2024-0909
CVE.ORG link : CVE-2024-0909
JSON object : View
Products Affected
tarassych
- anonymous_restricted_content
CWE