CyberRota Analysis
AI-GeneratedThe Members – Membership & User Role Editor Plugin for WordPress is susceptible to sensitive information exposure, allowing unauthenticated attackers to ascertain the existence and count of access-restricted posts. This vulnerability can be exploited to infer keywords and content from these posts, posing a risk to user privacy and data confidentiality. WordPress site administrators and users of this plugin should prioritize patching to mitigate potential data leaks.
Original NVD Description
The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.22 via the members_filter_protected_posts_for_rest. This makes it possible for unauthenticated attackers to extract determine the existence and exact count of access-restricted posts, and use per-page pagination as a boolean oracle to infer keywords and content contained within those hidden restricted posts.