← Back to search

CVE-2026-16603

7.5 HIGH

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows unauthenticated users to access protected content via the WordPress REST API, bypassing category-based restrictions.
Exploitability
Exploitation is relatively easy as no authentication is required, and only the core REST API needs to be accessed.
Blast radius
If exploited, it could lead to unauthorized access to sensitive post details, compromising user privacy.
Prioritized remediation
Update Passster WordPress plugin to version 4.3.6 or later to enforce category-based content protection on the REST API.
auth-bypasswebwp-plugin

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full content, title, and excerpt of category-locked posts through the core REST API.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-200

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.