CVE-2025-15674 LOW

CVE-2025-15674: Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API

Vendor Unknown
Product Passster
Published August 6, 2026
Last update August 6, 2026

CVSS base score

2.7/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read the content of protected pages and posts without knowing the password.

Explanation of Vulnerability in Simple Terms

02Summary

Passster versions before 4.3.7 contain a low-severity information disclosure vulnerability. An authenticated administrator with high privileges can read limited sensitive data through the affected component. The vulnerability requires network access and administrator-level credentials to exploit. Update to version 4.3.7 or later to remediate.

What an attacker can do

03Attacker Capabilities

Read limited sensitive information if they have administrator-level access.

Potential impact on your site

04Site Impact

Administrators with high privileges could access sensitive data; update Passster to 4.3.7+ to close the gap.

Conditions required to exploit

05Prerequisites

Attacker must be authenticated as a high-privilege administrator; network access required.

Key dates

06Disclosure timeline

August 6, 2026 CVE published