Restricted Site Access

Restricted Site Access has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2023; all 5 are fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 8.3 out of 10. Severity breakdown: 0 critical and 1 high. 2022 was the busiest year with 3 disclosures.

The most common weakness is Uncontrolled Resource Consumption, behind 2 of the records (40%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Improper Privilege Management.

Every one of the 5 issues recorded for Restricted Site Access has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Restricted Site Access is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.5/ 10
Patch Coverage100%
Open

0

Fixed

5

Get automatic notifications for all Restricted Site Access vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.3CVE-2023-28154

webpack JS package <= 5.75.0 - Sandbox Bypass

Read the full analysis

Vulnerability Records

5 records
Restricted Site Access banner
Latestv7.6.2

Restricted Site Access

10up

Author

10up

4.8(62)
96/100
Last Updated
2026-08-27 (16d ago)
Active Installs
10,000+
Downloads
1,221,414
Requires WP
6.9+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2009-08-17 (17y ago)

Limit access your site to visitors who are logged in or accessing the site from a set of specified IP addresses. Send restricted visitors to the log in page, redirect them, or display a message or page. A great solution for Extranets, publicly hosted Intranets, or parallel development / staging sites. Adds a number of new configuration options to the Reading settings panel as well as the Network Settings panel in multisite. From these panels you can: Enable or disable site restriction Change the restriction behavior: send to login, redirect, display a message, display a page Add IP addresses to an unrestricted list, including ranges Quickly add your current IP to the unrestricted list Customize the redirect location, including an option to send them to the same requested path and set the HTTP status code for SEO friendliness Define a simple message to show restricted visitors, or select a page to show them – great for “coming soon” teasers!

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C