← Back to search

CVE-2026-16604

7.5 HIGH

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows unauthenticated users to view password-protected content without entering a password, compromising data confidentiality.
Exploitability
Exploitation is relatively easy as no authentication is required; attackers need only access the affected plugin version.
Blast radius
If exploited, it could lead to unauthorized exposure of sensitive information on public pages.
Prioritized remediation
Update Passster WordPress plugin to version 4.3.6 or later immediately.
webauth-bypassconfidentiality

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-200

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.