Impact
The Passster WordPress plugin, before version 4.3.6, outputs the content of password‑protected blocks before verifying the password, allowing any visitor to view the protected material without authentication. This flaw represents an unrestricted information disclosure vulnerability (CWE‑200) that bypasses the intended access control and could reveal sensitive data embedded in the blocks.
Affected Systems
The vulnerability affects installations of the Passster plugin for WordPress running any version earlier than 4.3.6. No other vendors, products, or versions are currently known to be impacted.
Risk and Exploitability
Because the defect is triggered prior to authentication, it can be exploited by simply sending an HTTP request to a page containing a protected block. The attack requires no credentials, making it highly likely to be abused. No CVSS score is available, yet the nature of the flaw implies a severe information‑disclosure risk. The vulnerability is not listed in CISA's KEV catalog and no exploit probability is published.
OpenCVE Enrichment