Unrated severityNVD Advisory· Published Aug 5, 2026· Updated Aug 5, 2026
Content Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure via Core REST API
CVE-2026-16603
Description
The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full content, title, and excerpt of category-locked posts through the core REST API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/ec56a66e-e98a-4260-a0af-3ef6905ce839/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.