CyberRota Analysis
AI-GeneratedThe Gutentor WordPress plugin prior to version 4.0.6 has a vulnerability that allows authenticated users with Subscriber roles to access plaintext passwords of password-protected posts due to improper context restrictions on a REST endpoint. This exposure could lead to unauthorized access to sensitive content, compromising user privacy and security. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Gutentor WordPress plugin before 4.0.6 does not apply the correct context restriction to one of its REST endpoints, exposing the plaintext passwords of password-protected posts to any authenticated user with at least the Subscriber role.