CVE-2026-15939: Simple Restrict < 1.2.9 - Contributor+ Restricted Content Disclosure via REST API
The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission system, allowing users with contributor-level access or above to read the content of restricted posts and pages they were never granted access to.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Simple Restrictto a version that resolves this vulnerability.Fixed in 1.2.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15939?
The severity of CVE-2026-15939 is rated at 35.
How do I fix CVE-2026-15939?
To fix CVE-2026-15939, update the Simple Restrict WordPress plugin to version 1.2.9 or later.
What is the main issue in CVE-2026-15939?
CVE-2026-15939 allows unauthorized access to restricted content through the REST API due to improper permission checks.
Which software is affected by CVE-2026-15939?
CVE-2026-15939 affects the Simple Restrict WordPress plugin prior to version 1.2.9.
When was CVE-2026-15939 published?
CVE-2026-15939 was published on August 2, 2026.