SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78153

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Restrict User Access plugin for WordPress versions prior to 2.8.1 is vulnerable due to improper normalization of REST API routes, enabling unauthenticated users to bypass content protection measures. This flaw allows unauthorized access to restricted content and the ability to enumerate user accounts. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exposure.

CVE
CVE-2026-78153
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%
WordPress

Original NVD Description

The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users.