The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass global password protection, comparing them as an unanchored substring of the request URI rather than against the resolved route, allowing an unauthenticated attacker to read the content of globally password-protected posts and pages.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 21 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-284 |
Fri, 21 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 |
Fri, 21 Aug 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass global password protection, comparing them as an unanchored substring of the request URI rather than against the resolved route, allowing an unauthenticated attacker to read the content of globally password-protected posts and pages. | |
| Title | Content Protector (Passster) < 4.3.9 - Unauthenticated Protected Content Disclosure via REST Path Allowlist Bypass | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-21T12:47:20.891Z
Reserved: 2026-07-27T13:36:40.825Z
Link: CVE-2026-17559
No data.
Status : Received
Published: 2026-08-21T12:16:24.750
Modified: 2026-08-21T13:16:54.783
Link: CVE-2026-17559
No data.
OpenCVE Enrichment
Updated: 2026-08-21T13:30:04Z