Executive brief
Content Control is a WordPress plugin used by site administrators to restrict access to specific content based on user roles or login status. A security flaw in versions 2.6.5 and earlier allows unauthenticated visitors to bypass these restrictions, potentially leading to the exposure of private or sensitive information that should only be visible to authorized users. While the impact is considered moderate, it undermines the primary purpose of the plugin for site privacy.
Technical details
The Content Control plugin for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862) in versions up to and including 2.6.5. This vulnerability allows an unauthenticated remote attacker to bypass intended content restrictions and view protected data. The attack vector is network-based and requires no special privileges or user interaction. As of the advisory date, no official patch has been confirmed, though users are advised to monitor for updates from the developer, Code Atlantic LLC.
Affected products
- Code Atlantic LLC Content Control <= 2.6.5
Timeline
- 2026-01-26: other: Vulnerability reported by researcher Que Thanh Tuan
- 2026-07-22: advisory: Patchstack published the vulnerability details
- 2026-07-23: disclosed: CVE published to NVD