{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/page-and-post-restriction--1.4.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-12000"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Page and Post Restriction (\u003c= 1.4.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Page and Post Restriction plugin for WordPress (versions 1.4.0 and below) contains a critical logical flaw that results in sensitive information exposure. The vulnerability exists because the plugin's REST API protection mechanisms fail to verify the global security toggles intended to make all pages and posts private. While the plugin correctly restricts access via the frontend, the REST API guards only evaluate per-page/per-post metabox configurations. Consequently, global privacy settings ('Make all Pages Private' and 'Make all Posts Private') are ignored during REST API requests to /wp-json/wp/v2/pages and /wp-json/wp/v2/posts. An unauthenticated attacker can exploit this discrepancy to bypass intended access controls and retrieve the full content of any published post or page on an affected WordPress installation. This impact is significant for organizations relying on the plugin to protect private or sensitive internal content that would otherwise be exposed through the public-facing REST API.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated attackers to exfiltrate private post and page content, leading to unauthorized information disclosure. This bypasses the site's security policy, potentially exposing draft content, internal communications, or sensitive documentation intended only for authorized users. The scope of impact is contingent on the site administrator having enabled the 'Make all Pages Private' or 'Make all Posts Private' settings within the plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Page and Post Restriction plugin to a patched version beyond 1.4.0 immediately to restore REST API authorization logic.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for high-frequency requests to \u003ccode\u003e/wp-json/wp/v2/posts/\u003c/code\u003e and \u003ccode\u003e/wp-json/wp/v2/pages/\u003c/code\u003e from unauthenticated or suspicious external IP addresses.\u003c/li\u003e\n\u003cli\u003eConsider disabling the WordPress REST API entirely if it is not required for site functionality, or implement a Web Application Firewall (WAF) rule to block unauthenticated access to these specific sensitive endpoints if remediation cannot be applied immediately.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T09:15:51Z","date_published":"2026-08-05T09:15:51Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wp-papr-info-leak/","summary":"The Page and Post Restriction plugin for WordPress versions 1.4.0 and earlier fails to enforce global privacy settings on REST API endpoints, enabling unauthenticated access to restricted content.","title":"Sensitive Information Exposure in Page and Post Restriction WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-wp-papr-info-leak/"}],"language":"en","title":"CraftedSignal Threat Feed - Page and Post Restriction (\u003c= 1.4.0)","version":"https://jsonfeed.org/version/1.1"}