← WordPress Vulnerabilities
WordPress security by component

Passster – Password Protect Pages and Content

Passster – Password Protect Pages and Content (passster) is a WordPress plugin with 6 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 7.5.

Plugin slug: passster

CVE-2026-16604: Passster exposes password-protected block content in public responses

Passster before 4.3.6 includes password-protected block content in the public page response before it verifies the supplied password. An unauthenticated visitor can inspect the returned HTML or page data and recover the protected material without knowing the password. This unscored record received deeper review because it is an unauthenticated content-disclosure primitive. The CNA does not identify the response field or markup location that contains the hidden content.

PublishedAug 05, 2026
Known safe version4.3.6
Published vulnerabilities for passster
Safe version
Aug 05, 2026 CVE-2026-16604
Passster exposes password-protected block content in public responses
Passster before 4.3.6 includes password-protected block content in the public page response before it verifies the supplied password. An unauthenticated visitor can inspect the returned HTML or page data and recover the protected material without knowing the password. This unscored record received deeper review because it is an unauthenticated content-disclosure primitive. The CNA does not identify the response field or markup location that contains the hidden content.
4.3.6
CVE7.5
NVDPending
Aug 05, 2026 CVE-2026-16603
Passster category protection is bypassed through the WordPress REST API
Passster before 4.3.6 does not apply its category-based access restrictions to the core WordPress REST API. An unauthenticated visitor can request affected posts through the API and receive their full title, excerpt and content despite the category lock. This unscored record received deeper review because it is an unauthenticated protected-content disclosure primitive. The CNA does not disclose whether every core post endpoint or only particular response contexts are affected.
4.3.6
CVE7.5
NVDPending
Aug 05, 2026 CVE-2026-16602
Passster REST endpoint exposes draft, private and pending posts
Passster before 4.3.6 does not check a post's publication status before an unauthenticated REST endpoint returns its content. On sites with a captcha provider configured, an unauthenticated visitor can retrieve draft, private and pending posts that should not be public. This unscored record received deeper review because it exposes non-public content without authentication. The CNA does not disclose the REST route, request parameter or captcha-state requirements beyond the provider configuration.
4.3.6
CVE7.5
NVDPending
Jan 07, 2025 CVE-2024-11282
Passster – Password Protect Pages and Content: Sensitive information exposure
Passster – Password Protect Pages and Content is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.3
NVD7.5
Feb 29, 2024 CVE-2024-0616
Passster – Password Protect Pages and Content: Sensitive information exposure
Passster – Password Protect Pages and Content is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.3
NVD5.3
Oct 17, 2022 CVE-2022-3206
Passster: A security weakness
Passster is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.9
NVD5.9