{"id":"CVE-2026-16604","published":"2026-08-05T07:16:36.107","lastModified":"2026-08-05T16:16:52.820","description":"The Passster  WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-200"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/6a3222e3-352f-4fe8-b17f-b2980c3528e4/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated users to view password-protected content without entering a password, compromising data confidentiality.","exploitability":"Exploitation is relatively easy as no authentication is required; attackers need only access the affected plugin version.","blast_radius":"If exploited, it could lead to unauthorized exposure of sensitive information on public pages.","remediation":"Update Passster WordPress plugin to version 4.3.6 or later immediately.","tags":["web","auth-bypass","confidentiality"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:57:41.014Z"}}