Security Advisory

CVE-2026-17559

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-21 11:40:41
Last updated 2026-08-21 12:47:20
Assigner WPScan
CVSS score 5.3
State PUBLISHED

Description

The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass global password protection, comparing them as an unanchored substring of the request URI rather than against the resolved route, allowing an unauthenticated attacker to read the content of globally password-protected posts and pages.