Retour à la veille

CVE-2026-90952

Publié : 2 octobre 2026
Modifié : 2 octobre 2026
Lien officiel NVD
Score CVSS
5.3
MEDIUM

Description détaillée

The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Références et Patchs