PT-2026-57375 · WordPress · Members – Membership & User Role Editor Plugin
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Members – Membership & User Role Editor Plugin versions prior to 3.2.23
Description
An issue exists that allows unauthenticated attackers to expose sensitive information through the
members filter protected posts for rest function. This flaw enables the determination of the existence and exact count of access-restricted posts. Furthermore, attackers can utilize per-page pagination as a boolean oracle—a technique where a binary response (true/false) is used to deduce hidden data—to infer keywords and content within these restricted posts.Recommendations
Update the plugin to a version newer than 3.2.22.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Members – Membership & User Role Editor Plugin