{"id":"CVE-2026-16603","published":"2026-08-05T07:16:36.003","lastModified":"2026-08-05T16:16:52.670","description":"The Passster  WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full content, title, and excerpt of category-locked posts through the core REST API.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-200"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/ec56a66e-e98a-4260-a0af-3ef6905ce839/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated users to access protected content via the WordPress REST API, bypassing category-based restrictions.","exploitability":"Exploitation is relatively easy as no authentication is required, and only the core REST API needs to be accessed.","blast_radius":"If exploited, it could lead to unauthorized access to sensitive post details, compromising user privacy.","remediation":"Update Passster WordPress plugin to version 4.3.6 or later to enforce category-based content protection on the REST API.","tags":["auth-bypass","web","wp-plugin"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:57:36.046Z"}}