Description
The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password.
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Passster WordPress plugin, before version 4.3.6, outputs the content of password‑protected blocks before verifying the password, allowing any visitor to view the protected material without authentication. This flaw represents an unrestricted information disclosure vulnerability (CWE‑200) that bypasses the intended access control and could reveal sensitive data embedded in the blocks.

Affected Systems

The vulnerability affects installations of the Passster plugin for WordPress running any version earlier than 4.3.6. No other vendors, products, or versions are currently known to be impacted.

Risk and Exploitability

Because the defect is triggered prior to authentication, it can be exploited by simply sending an HTTP request to a page containing a protected block. The attack requires no credentials, making it highly likely to be abused. No CVSS score is available, yet the nature of the flaw implies a severe information‑disclosure risk. The vulnerability is not listed in CISA's KEV catalog and no exploit probability is published.

Generated by OpenCVE AI on August 5, 2026 at 07:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Passster plugin update (v4.3.6 or later).
  • If an immediate update cannot be performed, temporarily disable the Passster plugin or replace it with a secure alternative.
  • Eliminate or neutralize password‑protected blocks from publicly served pages until a safe update is installed.

Generated by OpenCVE AI on August 5, 2026 at 07:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password.
Title Content Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Content-Lock Block data-content Attribute
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-05T06:00:09.761Z

Reserved: 2026-07-22T14:20:57.363Z

Link: CVE-2026-16604

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T07:30:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor