WordPress Plugin Vulnerabilities
Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API
Description
The plugin does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read the content of protected pages and posts without knowing the password.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Pierre Rudloff
Submitter
Pierre Rudloff
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-03 (about 25 days ago)
Added
2026-08-03 (about 24 days ago)
Last Updated
2026-08-03 (about 24 days ago)