What is CVE-2026-14943?
This CVE affects the 'Password Protected' WordPress plugin before version 2.8.4, where unauthenticated users can bypass the sitewide password gate via the REST API if a specific option is enabled. It allows reading protected content, and the fix is to update the plugin to the latest version.
Azərbaycanca: Bu CVE, 'Password Protected' WordPress plaginin 2.8.4-dən əvvəlki versiyalarında aşkar edilib. Plaginin REST API girişini məhdudlaşdırmaması, autentifikasiya olunmamış istifadəçilərə sayt miqyasında tətbiq olunan parol müdafiəsini keçərək məzmunu oxumağa imkan verir. Həmin seçim aktiv olduqda, plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which WordPress plugin is affected by CVE-2026-14943?
This vulnerability affects the 'Password Protected' plugin versions before 2.8.4.
How to protect against CVE-2026-14943?
It is recommended to update the plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.