WordPress Plugin Vulnerabilities

Gutentor < 4.0.6 - Subscriber+ Password Protected Post Password Disclosure via REST API

Description

The plugin does not apply the correct context restriction to one of its REST endpoints, exposing the plaintext passwords of password-protected posts to any authenticated user with at least the Subscriber role.

Proof of Concept

Affects Plugins

Fixed in 4.0.6

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Ezekiel Victor
Submitter
Ezekiel Victor
Verified
Yes

Timeline

Publicly Published
2026-08-31 (about 2 days ago)
Added
2026-08-31 (about 1 day ago)
Last Updated
2026-08-31 (about 1 day ago)

Other