Junglewise Threat Intelligence

CVE-2026-12426: Members Membership & User Role Editor sensitive information exposure

CVE-2026-12426 · Severity: medium · CVSS 5.3 · Published 2026-07-11

Executive brief

The Members plugin for WordPress, which is used to manage user roles and restrict access to specific content, contains a security flaw that allows unauthorized individuals to see information about hidden posts. While the full content of protected posts is not directly visible, an attacker can determine how many restricted posts exist and use specialized techniques to guess their keywords and contents. This could lead to the exposure of sensitive or private information that was intended to be restricted to specific members.

Technical details

The Members plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 3.2.22 due to an issue in the 'members_filter_protected_posts_for_rest' function. This vulnerability allows unauthenticated attackers to interact with the WordPress REST API to determine the existence and exact count of access-restricted posts. Furthermore, by manipulating per-page pagination parameters, an attacker can use the API response as a boolean oracle to systematically infer keywords and specific content contained within hidden, restricted posts. This is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). A patch appears to be available in the plugin's trunk/latest versions.

Affected products

  • supercleanse Members – Membership & User Role Editor Plugin up to, and including, 3.2.22

Timeline

  • 2026-07-11: disclosed
  • 2026-07-11: advisory

References