---
id: CVE-2024-0682
title: >-
  The Page Restrict plugin for WordPress is vulnerable to information disclosure
  in all versions up to, and including, 2.5.5
summary: >-
  The Page Restrict plugin for WordPress is vulnerable to information disclosure
  in all versions up to, and including, 2.5.5. This is due to the plugin not
  properly restricting access to posts via the REST API when a page has been
  made pri…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-693
vendor: sivel
product: page_restrict
affected:
  - page_restrict <= 2.5.5
published: '2024-02-28'
updated: '2026-09-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-0682'
references:
  - url: 'https://wordpress.org/plugins/pagerestrict/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/63f98fd6-eee8-4281-98ea-a267d0442c85?source=cve
    label: security@wordfence.com
  - url: 'https://wordpress.org/plugins/pagerestrict/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/63f98fd6-eee8-4281-98ea-a267d0442c85?source=cve
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00496
epssPercentile: 0.41632
ingestedAt: '2026-09-01T13:27:06.868Z'
---

## Overview

The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5.5. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made private. This makes it possible for unauthenticated attackers to view protected posts.

## Affected

- `page_restrict <= 2.5.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
