Impact
The Passster WordPress plugin before version 4.3.6 fails to enforce its category‑based content protection on the WordPress core REST API, allowing any unauthenticated user to retrieve the full content, title, and excerpt of posts that are intended to be locked. This flaw permits unintended disclosure of privacy‑sensitive or confidential text to anyone who can query the REST endpoints.
Affected Systems
WordPress sites running the Passster plugin, any version earlier than 4.3.6, which enforce category locks but do not apply those rules to REST API requests.
Risk and Exploitability
Attackers can exploit the flaw by sending unauthenticated HTTP requests to the WordPress REST API endpoints exposed by the site. No exploitation prerequisites beyond external reach are required. Because the vulnerability is purely an information disclosure that requires no privileged access, the overall risk is moderate; however the potential impact on confidentiality is real. The EPSS score is unavailable, the CVE is not listed in the CISA KEV catalog, and no CVSS score is supplied by the vendor. The vulnerability is exploitable via normal HTTP traffic, making it accessible to anyone on the Internet.
OpenCVE Enrichment