The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass global password protection, comparing them as an unanchored substring of the request URI rather than against the resolved route, allowing an unauthenticated attacker to read the content of globally password-protected posts and pages.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Passster Project
Passster Project passster Wordpress Wordpress wordpress |
|
| Vendors & Products |
Passster Project
Passster Project passster Wordpress Wordpress wordpress |
Fri, 21 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-284 |
Fri, 21 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-284 |
Fri, 21 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 |
Fri, 21 Aug 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass global password protection, comparing them as an unanchored substring of the request URI rather than against the resolved route, allowing an unauthenticated attacker to read the content of globally password-protected posts and pages. | |
| Title | Content Protector (Passster) < 4.3.9 - Unauthenticated Protected Content Disclosure via REST Path Allowlist Bypass | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-08-21T11:40:41.735Z
Updated: 2026-08-21T12:47:20.891Z
Reserved: 2026-07-27T13:36:40.825Z
Link: CVE-2026-17559
Updated: 2026-08-21T12:47:16.827Z
Status : Deferred
Published: 2026-08-21T12:16:24.750
Modified: 2026-08-26T16:30:52.723
Link: CVE-2026-17559
No data.