PT-2026-79370 · WordPress · Passster

·

CVE-2026-17559

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Passster WordPress plugin versions prior to 4.3.9
Description The plugin fails to correctly match its public endpoint paths when determining which REST API requests should bypass global password protection. This occurs because the system compares paths as an unanchored substring of the request URI instead of using the resolved route. Consequently, an unauthenticated attacker can read the content of posts and pages that are globally password-protected.
Recommendations Update Passster WordPress plugin to version 4.3.9 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17559

Affected Products

Passster