Impact
The Passster WordPress plugin, in versions prior to 4.3.6, fails to enforce a post-status check before returning post content from an unauthenticated REST endpoint that is triggered by a captcha system. As a result, any visitor can retrieve the full body of draft, private, or pending posts, exposing internal content that should remain confidential. This breach of confidentiality can leak sensitive business information, user data, or intellectual property from the site.
Affected Systems
The vulnerability impacts the Passster plugin on WordPress sites using a captcha provider and running any Passster version earlier than 4.3.6. The issue is tied to the plugin’s integration with the captcha service and is not constrained to a particular WordPress theme or server configuration.
Risk and Exploitability
The flaw is exploitable by unauthenticated HTTP requests to a predictable REST endpoint; no authentication or elevated privileges are required. With the endpoint exposed, attackers can automatically submit the captcha challenge and receive post content. Because the vulnerability is straightforward to trigger and there is no mitigation in place by default, the risk rating is high. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, but the absence of a status check represents a critical access control failure.
OpenCVE Enrichment