Security Alert Summary
The Page and Post Restriction plugin for WordPress contains a vulnerability that can expose the full rendered content of published pages and posts when specific global privacy toggles are used. An attacker can retrieve content through WordPress core REST endpoints without authentication due to the plugin using an incomplete source of restricted IDs.
CVE Details
- CVE ID: CVE-2026-12000
- Affected component: Page and Post Restriction plugin for WordPress
- Affected versions: versions up to and including 1.4.0 (as stated in the vendor description)
- Published: August 5, 2026 at 8:16:30 AM
- Last modified: August 5, 2026 at 3:16:35 PM
- CVSS v3.1: Base Score 7.5, Severity HIGH, Vector string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Authentication / privileges / user interaction: No authentication required; privileges required: NONE; user interaction: NONE
- Primary impact: Confidentiality: HIGH; Integrity: NONE; Availability: NONE
- CWE: CWE-862
Technical Details
The plugin registers REST guards and filters that determine which pages and posts should be restricted. The vulnerable behavior arises because the REST guard papr_restrict_page_post_rest_api() and the the_posts filter registered by papr_filter_posts() source their list of restricted IDs exclusively from papr_get_restricted_posts_id(). That function only reads the per-page metabox options papr_allowed_redirect_for_pages and papr_allowed_redirect_for_posts and does not consult the two global toggles papr_access_for_only_loggedin and papr_access_for_only_loggedin_posts which the plugin UI documents as “Make all Pages Private” and “Make all Posts Private”.
Because the restricted-ID list used by the REST guards is incomplete, an unauthenticated requester can retrieve full rendered content via the WordPress core REST endpoints /wp-json/wp/v2/pages, /wp-json/wp/v2/pages/<id>, /wp-json/wp/v2/posts, and /wp-json/wp/v2/posts/<id> on sites that rely on the documented global toggles for privacy. The plugin still enforces a frontend security check via papr_restrict_logged_in_users(), but that check is bypassed for REST requests due to the missing global-toggle checks in the REST guard logic.
How This Could Impact Your Website
On a multi-user WordPress site, a site owner or administrator might enable the plugin’s documented global “Make all Pages Private” or “Make all Posts Private” toggles expecting published content to be hidden from unauthenticated visitors. However, internal staff or external contributors who publish content could have those pages accessible via REST endpoints if the plugin is at an affected version. An unauthenticated attacker could use the REST endpoints to read published page and post content that site owners intended to restrict.
Practical consequences include disclosure of sensitive content within pages or posts, which could include internal notes or contact details. That disclosure can increase the risk of targeted phishing or social engineering against staff or contractors if identifying information or internal processes are exposed. If you9re unsure whether your site is affected or how to assess your current user roles and plugins, it may be worth having a professional review your setup.
Recommended Actions
- Update the affected plugin as soon as a patched version is available.
- Review and reduce unnecessary user roles, especially contributors and other low-privilege publishing roles.
- Enforce strong passwords and enable two-factor authentication for editors and administrators.
- Remove unused or unmaintained plugins from the site.
- Monitor site activity and REST API access logs for unusual behavior or unexpected requests to
/wp-json/wp/v2/postsand/wp-json/wp/v2/pages.
If you9d like help reviewing your plugins, user roles, or overall WordPress security posture, our team at Freshy is happy to help.
References
- https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-and-post-restriction.php#L484
- https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-and-post-restriction.php#L69
- https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-and-post-restriction.php#L94
- https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-restriction-utility.php#L701
- https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-and-post-restriction.php#L484
- https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-and-post-restriction.php#L69
- https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-and-post-restriction.php#L94
- https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-restriction-utility.php#L701
- https://plugins.trac.wordpress.org/changeset?new=3578420%40page-and-post-restriction%2Ftags%2F1.4.2&old=3560846%40page-and-post-restriction%2Ftags%2F1.4.1
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f01302aa-00ef-440a-9c37-4fde6bb4bb4d?source=cve