CyberRota Analysis
AI-GeneratedThe Passster WordPress plugin prior to version 4.3.7 allows low-privilege users with the edit_posts capability to access globally password-protected content via the WordPress REST API, bypassing password restrictions. This vulnerability could lead to unauthorized exposure of sensitive information for any Contributor or higher role. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data leaks.
Original NVD Description
The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read the content of protected pages and posts without knowing the password.