CVE-2026-16604
Received Received - Intake

Passster WordPress Plugin Password Protection Bypass

Vulnerability report for CVE-2026-16604, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: WPScan

Description

The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
passster content_protector to 4.3.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Passster WordPress plugin before version 4.3.6 has a flaw where password-protected content is exposed in public page responses without first verifying the correct password. This allows unauthenticated users to view protected content without knowing the password.

Detection Guidance

Check if the Passster plugin version is below 4.3.6 by inspecting the WordPress plugin directory or admin panel. Look for exposed password-protected content in public page responses without authentication.

Impact Analysis

This vulnerability could allow unauthorized users to access sensitive or private content that was intended to be restricted. It may lead to data leaks, unauthorized access to confidential information, or exposure of protected materials.

Compliance Impact

This vulnerability could lead to non-compliance with data protection regulations like GDPR or HIPAA by exposing sensitive data to unauthorized parties. Organizations may face legal penalties, reputational damage, and loss of trust due to data breaches.

Mitigation Strategies

Update the Passster plugin to version 4.3.6 or later immediately. If updating is not possible, consider disabling the plugin temporarily until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16604. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart