← Back to search

CVE-2026-16602

7.5 HIGH

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows unauthenticated users to access non-public post content via an unsecured REST endpoint in Passster WordPress plugin versions before 4.3.6.
Exploitability
Exploitation is relatively easy as no authentication is required, and a captcha provider configuration is not necessary for the vulnerability to exist.
Blast radius
If exploited, this could lead to unauthorized disclosure of sensitive information such as draft or private posts.
Prioritized remediation
Update Passster WordPress plugin to version 4.3.6 or later immediately.
webwp-plugininfo-leak

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to disclose the content of non-public (draft, private, and pending) posts on sites that have a captcha provider configured.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-200

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.