Impact
A REST endpoint in the Gutentor WordPress plugin, used by versions earlier than 4.0.6, fails to enforce proper context restrictions. An authenticated user with the Subscriber role can make requests to this endpoint and receive plaintext passwords for password‑protected posts, allowing the actor to access these posts without the correct password.
Affected Systems
The Gutentor WordPress plugin, versions prior to 4.0.6, on installations of WordPress. Any site using this plugin without updating to the fixed release is vulnerable.
Risk and Exploitability
The vulnerability requires the attacker to be logged into WordPress with at least a Subscriber role, after which the endpoint can be called to retrieve post passwords. This poses a confidentiality risk by exposing credentials that grant access to protected content. No exploitation data or CVSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog; EPSS data is not available at this time.
OpenCVE Enrichment