cleantalk
Vulnerabilities and Security Researches

Wp Edit Password Protected – Create Member/User Only Page & Design Password Protected Form, CVE-2026-90952

CVE, Research URL

CVE-2026-90952

Published on
Oct 02, 2026
Research Description
The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide.
Affected versions
Min 2.0.0, max 2.0.7.
Status
vulnerable