CVE-2026-74943

Published Aug 18, 2026

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-74943 describes a vulnerability found in the "Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content" WordPress plugin, specifically in versions prior to 2.8.4. This flaw allows unauthenticated users to bypass the sitewide password protection. The vulnerability stems from an insufficient restriction of REST API access for authenticated users when a particular option is enabled. This oversight permits unauthenticated visitors to read content that should otherwise be protected, including account identifiers, by directly accessing the REST API. This issue is a re-introduction of a previously patched vulnerability, CVE-2024-0437, which was initially fixed in version 2.6.7 but reappeared in version 2.6.8 of the plugin.

Description
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Source
security@mozilla.org
NVD status
Modified
Products
firefox, thunderbird

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

nvd@nist.gov
CWE-416
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-416

Social media

Hype score
Not currently trending

Configurations