AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2025-15674

LOW · CVSS 2.7 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Passster WordPress plugin prior to version 4.3.7 allows low-privilege users with the edit_posts capability to access globally password-protected content via the WordPress REST API, bypassing password restrictions. This vulnerability could lead to unauthorized exposure of sensitive information for any Contributor or higher role. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data leaks.

CVE
CVE-2025-15674
Severity
LOW
CVSS
2.7
EPSS
0.22%
WordPress

Original NVD Description

The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read the content of protected pages and posts without knowing the password.