AI description
CVE-2026-74943 describes a vulnerability found in the "Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content" WordPress plugin, specifically in versions prior to 2.8.4. This flaw allows unauthenticated users to bypass the sitewide password protection. The vulnerability stems from an insufficient restriction of REST API access for authenticated users when a particular option is enabled. This oversight permits unauthenticated visitors to read content that should otherwise be protected, including account identifiers, by directly accessing the REST API. This issue is a re-introduction of a previously patched vulnerability, CVE-2024-0437, which was initially fixed in version 2.6.7 but reappeared in version 2.6.8 of the plugin.
- Description
- Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- Source
- security@mozilla.org
- NVD status
- Modified
- Products
- firefox, thunderbird
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "FD8DBFC4-10A7-41E2-B754-71CC6FEEBB5C",
"versionEndExcluding": "115.39.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "502016C0-F897-4F18-BFC7-301B71D93E4D",
"versionEndExcluding": "140.14.0",
"versionStartIncluding": "116.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5D58C9D3-E300-408A-ABF2-6E2BB49AB921",
"versionEndExcluding": "153.1.0",
"versionStartIncluding": "141.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "4E2EC2AA-23B2-45C9-8594-DF80A0D800A7",
"versionEndExcluding": "140.14.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"matchCriteriaId": "47206424-A249-46CE-9776-F45A49344204",
"versionEndExcluding": "153.1.0",
"versionStartIncluding": "141.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]