Description
The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full content, title, and excerpt of category-locked posts through the core REST API.
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Passster WordPress plugin before version 4.3.6 fails to enforce its category‑based content protection on the WordPress core REST API, allowing any unauthenticated user to retrieve the full content, title, and excerpt of posts that are intended to be locked. This flaw permits unintended disclosure of privacy‑sensitive or confidential text to anyone who can query the REST endpoints.

Affected Systems

WordPress sites running the Passster plugin, any version earlier than 4.3.6, which enforce category locks but do not apply those rules to REST API requests.

Risk and Exploitability

Attackers can exploit the flaw by sending unauthenticated HTTP requests to the WordPress REST API endpoints exposed by the site. No exploitation prerequisites beyond external reach are required. Because the vulnerability is purely an information disclosure that requires no privileged access, the overall risk is moderate; however the potential impact on confidentiality is real. The EPSS score is unavailable, the CVE is not listed in the CISA KEV catalog, and no CVSS score is supplied by the vendor. The vulnerability is exploitable via normal HTTP traffic, making it accessible to anyone on the Internet.

Generated by OpenCVE AI on August 5, 2026 at 07:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Passster plugin to version 4.3.6 or later to restore proper category‑based protection in the REST API.
  • If a plugin upgrade cannot be performed immediately, block or filter unauthenticated requests to the WordPress REST API routes that expose content—for example, by configuring the web server or using a security plugin to restrict REST access to logged‑in users.
  • If Category‑Based protection is required without an immediate upgrade, consider removing or disabling the Passster plugin until a patched version is available, or use a firewall or reverse‑proxy rule to strip the REST endpoint from public exposure.

Generated by OpenCVE AI on August 5, 2026 at 07:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-862

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full content, title, and excerpt of category-locked posts through the core REST API.
Title Content Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure via Core REST API
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-05T06:00:09.588Z

Reserved: 2026-07-22T14:20:50.104Z

Link: CVE-2026-16603

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T07:30:16Z

Weaknesses