VYPR
High severity7.5NVD Advisory· Published Aug 5, 2026· Updated Aug 26, 2026

CVE-2026-16604

CVE-2026-16604

Description

The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

1