What is CVE-2026-15939?
This vulnerability in the Simple Restrict WordPress plugin before version 1.2.9 fails to enforce content-restriction permission checks on the REST API, relying on a generic capability check instead of its own permission system. As a result, any authenticated user can bypass restrictions and access restricted content. Immediate plugin update to the latest version is advised.
Azərbaycanca: Bu boşluq Simple Restrict WordPress plagininin 1.2.9-dan əvvəlki versiyalarında REST API üzərində məzmun məhdudiyyəti icazə yoxlamasını düzgün tətbiq etmir. Nəticədə, autentifikasiya olunmuş istənilən istifadəçi plaginin öz icazə sistemindən yan keçərək məhdudlaşdırılmış məzmuna giriş əldə edə bilər. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Simple Restrict plugin are affected by CVE-2026-15939?
This vulnerability affects the Simple Restrict WordPress plugin versions prior to 1.2.9.
What can an authenticated user achieve by exploiting CVE-2026-15939?
Any authenticated user can bypass the plugin's own permission system and access restricted content.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.