Unauthorized Access to Non-Public Post Content in Passster Plugin for WordPress
CVE-2026-16602
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-16602?
The Passster plugin for WordPress prior to version 4.3.6 is vulnerable due to insufficient checks on post status when returning content from a REST endpoint. This flaw enables unauthorized users to access and disclose the content of private, draft, or pending posts on websites using a captcha provider. As a result, sensitive information that should be restricted can be exposed, potentially compromising the privacy and security of site content.
Affected Version(s)
Passster 0 < 4.3.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.