AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16602

HIGH · CVSS 7.5 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Passster WordPress plugin prior to version 4.3.6 is vulnerable due to a lack of post-status verification, which permits unauthenticated users to access and disclose the content of non-public posts, including drafts and private entries, through an exposed REST endpoint. This vulnerability poses a significant risk to site privacy and data confidentiality, particularly for websites utilizing a captcha provider. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data exposure risks.

CVE
CVE-2026-16602
Severity
HIGH
CVSS
7.5
EPSS
0.32%
WordPress

Original NVD Description

The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to disclose the content of non-public (draft, private, and pending) posts on sites that have a captcha provider configured.