Simple Restrict
Simple Restrict has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 5.0, and the most serious one scores 5.3 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 3 of the records (100%).
Every one of the 3 issues recorded for Simple Restrict has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, most of them (2) reported by Francesco Carlucci. Simple Restrict is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-11106Simple Restrict <= 1.2.7 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure
Read the full analysisVulnerability Records

Simple Restrict
Author
WP Chill
This plugin allows you to easily mark certain pages with “Permissions” and only users with those permissions will be allowed to see the contents of the page. Page Permissions: This plugin adds a new Permissions taxonomy to your pages. Administrators can create/assign new permissions from the Edit Page screen (you can also use the Quick Edit link). You can add/edit/delete permissions from the Permissions sub-menu under the Pages menu. Pages with no assigned permissions can be seen by everyone. User Permissions: Administrators can add/remove permissions from a user using the checkboxes on the Edit User screen. The All Users page has a column that shows the permissions assigned to each user. Restriction Message: If a page has permissions assigned, the content will only be visible to users that have one of those same permissions assigned. Otherwise, the content will be replaced by a generic message or a custom message which can be defined in the plugin settings using the standard WordPress editor (including the ability to add media and formatting). Redirect to login: Instead of a restriction message, you can choose to have users get redirected to the login page.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C