Restricted Site Access
Restricted Site Access has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2023; all 5 are fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 8.3 out of 10. Severity breakdown: 0 critical and 1 high. 2022 was the busiest year with 3 disclosures.
The most common weakness is Uncontrolled Resource Consumption, behind 2 of the records (40%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Improper Privilege Management.
Every one of the 5 issues recorded for Restricted Site Access has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Restricted Site Access is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2023-28154webpack JS package <= 5.75.0 - Sandbox Bypass
Read the full analysisVulnerability Records

Restricted Site Access
Author
10up
Limit access your site to visitors who are logged in or accessing the site from a set of specified IP addresses. Send restricted visitors to the log in page, redirect them, or display a message or page. A great solution for Extranets, publicly hosted Intranets, or parallel development / staging sites. Adds a number of new configuration options to the Reading settings panel as well as the Network Settings panel in multisite. From these panels you can: Enable or disable site restriction Change the restriction behavior: send to login, redirect, display a message, display a page Add IP addresses to an unrestricted list, including ranges Quickly add your current IP to the unrestricted list Customize the redirect location, including an option to send them to the same requested path and set the HTTP status code for SEO friendliness Define a simple message to show restricted visitors, or select a page to show them – great for “coming soon” teasers!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C