Impact
A REST endpoint in the Gutentor WordPress plugin, used by versions earlier than 4.0.6, fails to enforce proper context restrictions, representing an instance of CWE-200. An authenticated user with the Subscriber role can make requests to this endpoint and receive plaintext passwords for password‑protected posts, allowing the actor to access these posts without the correct password.
Affected Systems
The Gutentor WordPress plugin, versions prior to 4.0.6, on installations of WordPress. Any site using this plugin without updating to the fixed release is vulnerable.
Risk and Exploitability
The vulnerability requires the attacker to be logged into WordPress with at least a Subscriber role, after which the endpoint can be called to retrieve post passwords, exposing credentials that unlock protected content. The CVSS score of 4.3 indicates moderate severity, and the EPSS score of 0.00149 (~0.15%) suggests a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog, and no public exploitation data is known.
OpenCVE Enrichment