CVE-2026-16604

The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-05 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-16604

Mitre link : CVE-2026-16604

CVE.ORG link : CVE-2026-16604


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor