Impact
An unauthenticated attacker can exploit a side‑channel in the Members – Membership & User Role Editor Plugin’s REST API pagination to discover the existence and exact number of restricted posts. By repeatedly querying pages the attacker can determine which content is hidden and even infer keyword information about the protected posts. The flaw allows exposure of sensitive data that should remain private to authorized users.
Affected Systems
WordPress installations that use the Members – Membership & User Role Editor Plugin in versions up to and including 3.2.22 are impacted. The vulnerability arises from the members_filter_protected_posts_for_rest function in those releases.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% reflect a low probability of exploitation at the time of assessment, and the vulnerability is not listed in the CISA KEV catalog. Attackers can gain the described information without authentication by sending normal REST API requests, making the attack surface readily accessible from the public internet.
OpenCVE Enrichment