PoC Index82,564 CVEs with PoCs

CVE-2026-78153

Restrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass via REST API Route Normalization

MEDIUM 5.3EPSS 0.2%

The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users.

Affected
Restrict User Access
CVSS v3.1 WPSCAN
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.21% chance of exploitation in the next 30 days, 11th percentile
Published
2026-09-02

Proof-of-concept exploits (1)

References