CVE-2026-62040: WordPress Restrict User Access – Membership plugin with Force plugin <= 2.8.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in DEV Institute Restrict User Access – Membership Plugin with Force restrict-user-access allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restrict User Access – Membership Plugin with Force: from n/a through 2.8.1.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
The issue affects DEV Institute Restrict User Access – Membership Plugin with Force versions through 2.8.1. The available data does not identify a fixed version.
Does exploitation require authentication or user interaction?
The supplied vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required. Confidentiality impact is rated low, with no stated integrity or availability impact.
What configuration condition is associated with the vulnerability?
The issue is described as exploitation of incorrectly configured access-control security levels. The provided data does not specify which plugin settings or rules create the exposed condition.