WordPress · Members – Membership & User Role Editor Plugin · CVE-2026-12426
**Name of the Vulnerable Software and Affected Versions**
Members – Membership & User Role Editor Plugin versions prior to 3.2.23
**Description**
An issue exists that allows unauthenticated attackers to expose sensitive information through the `members filter protected posts for rest` function. This flaw enables the determination of the existence and exact count of access-restricted posts. Furthermore, attackers can utilize per-page pagination as a boolean oracle—a technique where a binary response (true/false) is used to deduce hidden data—to infer keywords and content within these restricted posts.
**Recommendations**
Update the plugin to a version newer than 3.2.22.