Impact
The Passster plugin for WordPress, in versions before 4.3.7, does not enforce proper permissions for the WordPress core REST API. Users that hold the edit_posts capability—every Contributor and above—can send API requests that bypass global password protection and retrieve the full text of password‑protected pages or posts. This flaw allows an attacker with such a role to read confidential or proprietary content without knowing the protecting password, thereby breaching confidentiality.
Affected Systems
WordPress sites that have the Passster plugin installed with a version earlier than 4.3.7, regardless of hosting platform or environment. The CNA lists the vendor as Unknown:Passster, so any site running the vulnerable plugin is affected.
Risk and Exploitability
The CVSS score of 2.7 indicates a low overall severity. The EPSS score is not available, implying no public exploitation data. The issue is not listed in CISA KEV. The attack path requires a valid Contributor‑level or higher account, which is common in many sites. An attacker only needs to call the REST API endpoints that expose protected content; no additional privileges or code execution are required. The main risk is inadvertent disclosure of sensitive content that should remain password‑protected, potentially leading to reputational or contractual damage if sensitive data is leaked.
OpenCVE Enrichment