CyberRota Analysis
AI-GeneratedThe Passster WordPress plugin prior to version 4.3.6 is vulnerable due to a lack of post-status verification, which permits unauthenticated users to access and disclose the content of non-public posts, including drafts and private entries, through an exposed REST endpoint. This vulnerability poses a significant risk to site privacy and data confidentiality, particularly for websites utilizing a captcha provider. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data exposure risks.
Original NVD Description
The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to disclose the content of non-public (draft, private, and pending) posts on sites that have a captcha provider configured.