Impact
The User Access Manager plugin does not apply its configured access restrictions to REST API requests. As a result, any unauthenticated user can retrieve the content of posts, pages, and custom post types that have been restricted to specific user groups. This flaw exposes information that site administrators intended to keep confidential.
Affected Systems
WordPress sites that have the User Access Manager plugin installed at a version older than 2.3.15 are affected. The vulnerability is confined to the plugin; no particular WordPress core version is cited.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The flaw does not require authentication; an attacker can simply send REST API requests to the exposed endpoints to download restricted content. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low current exploitation probability. Based on the description, it is inferred that an attacker can use standard REST API calls to gather this information from any public WordPress site using the vulnerable plugin.
OpenCVE Enrichment