PT-2026-79370 · WordPress · Passster
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Passster WordPress plugin versions prior to 4.3.9
Description
The plugin fails to correctly match its public endpoint paths when determining which REST API requests should bypass global password protection. This occurs because the system compares paths as an unanchored substring of the request URI instead of using the resolved route. Consequently, an unauthenticated attacker can read the content of posts and pages that are globally password-protected.
Recommendations
Update Passster WordPress plugin to version 4.3.9 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Passster