What the vulnerability does
01Description
The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read the content of protected pages and posts without knowing the password.
Explanation of Vulnerability in Simple Terms
02Summary
Passster versions before 4.3.7 contain a low-severity information disclosure vulnerability. An authenticated administrator with high privileges can read limited sensitive data through the affected component. The vulnerability requires network access and administrator-level credentials to exploit. Update to version 4.3.7 or later to remediate.
What an attacker can do
03Attacker Capabilities
Read limited sensitive information if they have administrator-level access.
Potential impact on your site
04Site Impact
Administrators with high privileges could access sensitive data; update Passster to 4.3.7+ to close the gap.
Conditions required to exploit
05Prerequisites
Attacker must be authenticated as a high-privilege administrator; network access required.
Key dates
06Disclosure timeline
August 6, 2026
CVE published