WordPress Plugin Vulnerabilities

Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API

Description

The plugin does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read the content of protected pages and posts without knowing the password.

Proof of Concept

Affects Plugins

Fixed in 4.3.7

References

Miscellaneous

Original Researcher
Pierre Rudloff
Submitter
Pierre Rudloff
Verified
Yes

Timeline

Publicly Published
2026-08-03 (about 25 days ago)
Added
2026-08-03 (about 24 days ago)
Last Updated
2026-08-03 (about 24 days ago)

Other