Description
The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read the content of protected pages and posts without knowing the password.
Published: 2026-08-06
Score: 2.7 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Passster plugin for WordPress, in versions before 4.3.7, does not enforce proper permissions for the WordPress core REST API. Users that hold the edit_posts capability—every Contributor and above—can send API requests that bypass global password protection and retrieve the full text of password‑protected pages or posts. This flaw allows an attacker with such a role to read confidential or proprietary content without knowing the protecting password, thereby breaching confidentiality.

Affected Systems

WordPress sites that have the Passster plugin installed with a version earlier than 4.3.7, regardless of hosting platform or environment. The CNA lists the vendor as Unknown:Passster, so any site running the vulnerable plugin is affected.

Risk and Exploitability

The CVSS score of 2.7 indicates a low overall severity. The EPSS score is not available, implying no public exploitation data. The issue is not listed in CISA KEV. The attack path requires a valid Contributor‑level or higher account, which is common in many sites. An attacker only needs to call the REST API endpoints that expose protected content; no additional privileges or code execution are required. The main risk is inadvertent disclosure of sensitive content that should remain password‑protected, potentially leading to reputational or contractual damage if sensitive data is leaked.

Generated by OpenCVE AI on August 7, 2026 at 01:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Passster to version 4.3.7 or newer, which restores proper access control for the REST API.
  • If an upgrade is infeasible, configure the REST API or WordPress settings to block requests to the protected endpoints for users with edit_posts capability, for example by removing or restricting the relevant REST routes.
  • Temporarily disable global password protection for content that does not require it, or convert password protection to per‑post rules that do not expose data via the REST API.
  • Review user roles and audit content that is globally password‑protected to ensure only authorized audiences can access it.

Generated by OpenCVE AI on August 7, 2026 at 01:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Passster Project
Passster Project passster
Wordpress
Wordpress wordpress
Vendors & Products Passster Project
Passster Project passster
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read the content of protected pages and posts without knowing the password.
Title Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Passster Project Passster
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-06T17:17:18.142Z

Reserved: 2026-07-22T14:20:59.606Z

Link: CVE-2025-15674

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:00:05Z

Weaknesses

No weakness.