Improper Input Validation in Passster Plugin for WordPress
CVE-2026-17559
Key Information:
Badges
What is CVE-2026-17559?
The Passster plugin for WordPress prior to version 4.3.9 contains a flaw that allows unauthenticated attackers to bypass globally set password protections due to improper comparison of REST API endpoint paths. Instead of accurately matching resolved routes, the plugin evaluates paths as unanchored substrings of the request URI. This oversight enables attackers to access and read the content of posts and pages that are intended to be password-protected.
Affected Version(s)
Passster 4.3.3 < 4.3.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved