CVE-2025-15674: Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API
The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the editposts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read the content of protected pages and posts without knowing the password.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Passster (Content Protector) for WordPressto a version that resolves this vulnerability.Fixed in 4.3.7
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15674?
CVE-2025-15674 has a low severity rating of 2.7.
How do I fix CVE-2025-15674?
To fix CVE-2025-15674, update the Passster plugin to version 4.3.7 or later.
What is the risk associated with CVE-2025-15674?
CVE-2025-15674 poses a risk level of 16, indicating a potential impact on protected content disclosure.
Who is affected by CVE-2025-15674?
CVE-2025-15674 affects users of the Passster plugin on WordPress who have Contributor or higher roles.
What type of vulnerability is CVE-2025-15674?
CVE-2025-15674 is a content disclosure vulnerability via the WordPress core REST API.