Security Advisory
CVE-2026-16604
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password.