
CVE-2026-15939 The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying … https://www.cve.org/CVERecord?id=CVE-2026-15939
Post summary
CVE-2026-15939 identifies a permission-check flaw in the Simple Restrict WordPress plugin affecting the REST API; no PoC, exploit, or mitigation details are included.


